<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.4</oval:schema_version>
    <oval:timestamp>2015-09-03T06:26:41.802-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:29463" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1039 -- ntp security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>ntp</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1039.html" ref_id="RHSA-2009:1039"/>
        <reference source="CESA-2009:1039" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-May/015881.html" ref_id="CESA-2009:1039-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0159" ref_id="CVE-2009-0159"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1252" ref_id="CVE-2009-1252"/>
        <description>An updated ntp package that fixes two security issues is now available for
Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:02.682-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:46.340-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:41.532-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="ntp is earlier than 0:4.2.2p1-9.el5_3.2" test_ref="oval:org.mitre.oval:tst:141024"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="ntp is earlier than 0:4.2.2p1-9.el5.centos.2" test_ref="oval:org.mitre.oval:tst:141115"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29446" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0473 -- kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0473.html" ref_id="RHSA-2009:0473"/>
        <reference source="CESA-2009:0473" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-May/015845.html" ref_id="CESA-2009:0473-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4307" ref_id="CVE-2008-4307"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0787" ref_id="CVE-2009-0787"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0834" ref_id="CVE-2009-0834"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1336" ref_id="CVE-2009-1336"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1337" ref_id="CVE-2009-1337"/>
        <description>Updated kernel packages that fix several security issues and several bugs
are now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The kernel packages contain the Linux kernel, the core of any Linux
operating system.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:10.669-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:46.014-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:41.061-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:140816"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:140921"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:140945"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:141160"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:141042"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:140988"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:140909"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:140975"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:140426"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:140924"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29396" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1095 -- firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1095.html" ref_id="RHSA-2009:1095"/>
        <reference source="CESA-2009:1095" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-June/015993.html" ref_id="CESA-2009:1095-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1392" ref_id="CVE-2009-1392"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1832" ref_id="CVE-2009-1832"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1833" ref_id="CVE-2009-1833"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1834" ref_id="CVE-2009-1834"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1835" ref_id="CVE-2009-1835"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1836" ref_id="CVE-2009-1836"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1837" ref_id="CVE-2009-1837"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1838" ref_id="CVE-2009-1838"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1839" ref_id="CVE-2009-1839"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1840" ref_id="CVE-2009-1840"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1841" ref_id="CVE-2009-1841"/>
        <description>Updated firefox packages that fix several security issues are now available
for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-1392, CVE-2009-1832, CVE-2009-1833, CVE-2009-1837, CVE-2009-1838,
CVE-2009-1841)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:04.719-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:45.493-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:40.318-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:140443"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:140856"/>
            <criterion comment="firefox is earlier than 0:3.0.11-2.el5_3" test_ref="oval:org.mitre.oval:tst:140701"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:140702"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="firefox is earlier than 0:3.0.11-4.el4" test_ref="oval:org.mitre.oval:tst:141044"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:3.0.11-2.el5.centos" test_ref="oval:org.mitre.oval:tst:140819"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.11-3.el5" test_ref="oval:org.mitre.oval:tst:140998"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5" test_ref="oval:org.mitre.oval:tst:141077"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5" test_ref="oval:org.mitre.oval:tst:140919"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29387" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0411 -- device-mapper-multipath security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>device-mapper-multipath</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0411.html" ref_id="RHSA-2009:0411"/>
        <reference source="CESA-2009:0411" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-April/015739.html" ref_id="CESA-2009:0411-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0115" ref_id="CVE-2009-0115"/>
        <description>Updated device-mapper-multipath packages that fix a security issue are now
available for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The device-mapper multipath packages provide tools to manage multipath
devices by issuing instructions to the device-mapper multipath kernel
module, and by managing the creation and removal of partitions for
device-mapper devices.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:12.129-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:45.300-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:40.167-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="device-mapper-multipath is earlier than 0:0.4.5-31.el4_7.1" test_ref="oval:org.mitre.oval:tst:139942"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="device-mapper-multipath is earlier than 0:0.4.7-23.el5_3.2" test_ref="oval:org.mitre.oval:tst:139876"/>
            <criterion comment="kpartx is earlier than 0:0.4.7-23.el5_3.2" test_ref="oval:org.mitre.oval:tst:139382"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29382" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1619 -- dstat security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>dstat</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1619.html" ref_id="RHSA-2009:1619"/>
        <reference source="CESA-2009:1619" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-December/016366.html" ref_id="CESA-2009:1619-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3894" ref_id="CVE-2009-3894"/>
        <description>An updated dstat package that fixes one security issue is now available for
Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Dstat is a versatile replacement for the vmstat, iostat, and netstat tools.
Dstat can be used for performance tuning tests, benchmarks, and
troubleshooting.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:37:46.895-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:45.188-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:40.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="dstat is earlier than 0:0.6.6-3.el5_4.1" test_ref="oval:org.mitre.oval:tst:139764"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29381" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0315 -- firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0315.html" ref_id="RHSA-2009:0315"/>
        <reference source="CESA-2009:0315" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-April/015752.html" ref_id="CESA-2009:0315-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0040" ref_id="CVE-2009-0040"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0771" ref_id="CVE-2009-0771"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0772" ref_id="CVE-2009-0772"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0773" ref_id="CVE-2009-0773"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0774" ref_id="CVE-2009-0774"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0775" ref_id="CVE-2009-0775"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0776" ref_id="CVE-2009-0776"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0777" ref_id="CVE-2009-0777"/>
        <description>An updated firefox package that fixes various security issues is now
available for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
Mozilla Firefox is an open source Web browser.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-0040, CVE-2009-0771, CVE-2009-0772, CVE-2009-0773, CVE-2009-0774,
CVE-2009-0775)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:08.299-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:44.912-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:39.706-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:140359"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:140178"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:140357"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:3.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:140183"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="firefox is earlier than 0:3.0.7-1.el4" test_ref="oval:org.mitre.oval:tst:140385"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:3.0.7-1.el5.centos" test_ref="oval:org.mitre.oval:tst:140353"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29380" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0457 -- libwmf security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>libwmf</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0457.html" ref_id="RHSA-2009:0457"/>
        <reference source="CESA-2009:0457" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-May/015871.html" ref_id="CESA-2009:0457-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1364" ref_id="CVE-2009-1364"/>
        <description>Updated libwmf packages that fix one security issue are now available for
Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
libwmf is a library for reading and converting Windows Metafile Format
(WMF) vector graphics. libwmf is used by applications such as GIMP and
ImageMagick.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:31.521-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:44.777-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:39.556-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libwmf-devel is earlier than 0:0.2.8.4-10.2" test_ref="oval:org.mitre.oval:tst:140042"/>
            <criterion comment="libwmf is earlier than 0:0.2.8.4-10.2" test_ref="oval:org.mitre.oval:tst:139931"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libwmf is earlier than 0:0.2.8.3-5.8" test_ref="oval:org.mitre.oval:tst:140307"/>
            <criterion comment="libwmf-devel is earlier than 0:0.2.8.3-5.8" test_ref="oval:org.mitre.oval:tst:140274"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29379" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1427 -- fetchmail security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>fetchmail</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1427.html" ref_id="RHSA-2009:1427"/>
        <reference source="CESA-2009:1427" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-September/016125.html" ref_id="CESA-2009:1427-CentOS 3"/>
        <reference source="CESA-2009:1427" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-September/016159.html" ref_id="CESA-2009:1427-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4565" ref_id="CVE-2007-4565"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2711" ref_id="CVE-2008-2711"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2666" ref_id="CVE-2009-2666"/>
        <description>An updated fetchmail package that fixes multiple security issues is now
available for Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:32.805-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:44.508-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:39.285-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="fetchmail is earlier than 0:6.3.6-1.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:140338"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="fetchmail is earlier than 0:6.2.0-3.el3.5" test_ref="oval:org.mitre.oval:tst:140731"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="fetchmail is earlier than 0:6.2.5-6.0.1.el4_8.1" test_ref="oval:org.mitre.oval:tst:140541"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29372" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0010 -- squirrelmail security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>squirrelmail</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0010.html" ref_id="RHSA-2009:0010"/>
        <reference source="CESA-2009:0010" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-January/015540.html" ref_id="CESA-2009:0010-CentOS 3"/>
        <reference source="CESA-2009:0010" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-January/015546.html" ref_id="CESA-2009:0010-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2379" ref_id="CVE-2008-2379"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3663" ref_id="CVE-2008-3663"/>
        <description>An updated squirrelmail package that resolves various security issues is
now available for Red Hat Enterprise Linux 3, 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
SquirrelMail is an easy-to-configure, standards-based, webmail package
written in PHP. It includes built-in PHP support for the IMAP and SMTP
protocols, and pure HTML 4.0 page-rendering (with no JavaScript required)
for maximum browser-compatibility, strong MIME support, address books, and
folder manipulation.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:39:55.532-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:44.179-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:38.972-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el5_2.2" test_ref="oval:org.mitre.oval:tst:140516"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-8.el3" test_ref="oval:org.mitre.oval:tst:139889"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el4_7.2" test_ref="oval:org.mitre.oval:tst:140185"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el5.centos.2" test_ref="oval:org.mitre.oval:tst:140526"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29371" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0344 -- libsoup security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>evolution28-libsoup</product>
          <product>libsoup</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0344.html" ref_id="RHSA-2009:0344"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0585" ref_id="CVE-2009-0585"/>
        <description>Updated libsoup and evolution28-libsoup packages that fix a security issue
are now available for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
libsoup is an HTTP client/library implementation for GNOME written in C. It
was originally part of a SOAP (Simple Object Access Protocol)
implementation called Soup, but the SOAP and non-SOAP parts have now been
split into separate packages.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:39:59.760-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:44.052-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:38.785-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libsoup-devel is earlier than 0:2.2.98-2.el5_3.1" test_ref="oval:org.mitre.oval:tst:140392"/>
            <criterion comment="libsoup is earlier than 0:2.2.98-2.el5_3.1" test_ref="oval:org.mitre.oval:tst:140462"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="evolution28-libsoup is earlier than 0:2.2.98-5.el4.1" test_ref="oval:org.mitre.oval:tst:140243"/>
            <criterion comment="evolution28-libsoup-devel is earlier than 0:2.2.98-5.el4.1" test_ref="oval:org.mitre.oval:tst:140436"/>
            <criterion comment="libsoup is earlier than 0:2.2.1-4.el4.1" test_ref="oval:org.mitre.oval:tst:140238"/>
            <criterion comment="libsoup-devel is earlier than 0:2.2.1-4.el4.1" test_ref="oval:org.mitre.oval:tst:140412"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29369" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1321 -- nfs-utils security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>nfs-utils</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1321.html" ref_id="RHSA-2009:1321"/>
        <reference source="CESA-2009:1321" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-September/016148.html" ref_id="CESA-2009:1321-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4552" ref_id="CVE-2008-4552"/>
        <description>An updated nfs-utils package that fixes a security issue and several bugs
is now available.
This update has been rated as having low security impact by the Red Hat
Security Response Team.
The nfs-utils package provides a daemon for the kernel NFS server and
related tools.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:29.574-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:43.900-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:38.636-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="nfs-utils is earlier than 1:1.0.9-42.el5" test_ref="oval:org.mitre.oval:tst:140674"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29367" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0261 -- vnc security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 3</platform>
          <product>vnc</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0261.html" ref_id="RHSA-2009:0261"/>
        <reference source="CESA-2009:0261" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-February/015629.html" ref_id="CESA-2009:0261-CentOS 3"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4770" ref_id="CVE-2008-4770"/>
        <description>Updated vnc packages to correct a security issue are now available for Red
Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:32.490-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:43.763-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:38.432-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="vnc is earlier than 0:4.0-0.beta4.1.8" test_ref="oval:org.mitre.oval:tst:140408"/>
            <criterion comment="vnc-server is earlier than 0:4.0-0.beta4.1.8" test_ref="oval:org.mitre.oval:tst:140140"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="vnc is earlier than 0:4.0-12.el4_7.1" test_ref="oval:org.mitre.oval:tst:139841"/>
            <criterion comment="vnc-server is earlier than 0:4.0-12.el4_7.1" test_ref="oval:org.mitre.oval:tst:140445"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="vnc is earlier than 0:4.1.2-14.el5_3.1" test_ref="oval:org.mitre.oval:tst:140288"/>
            <criterion comment="vnc-server is earlier than 0:4.1.2-14.el5_3.1" test_ref="oval:org.mitre.oval:tst:140351"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29365" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1601 -- kdelibs security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>kdelibs</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1601.html" ref_id="RHSA-2009:1601"/>
        <reference source="CESA-2009:1601" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-November/016337.html" ref_id="CESA-2009:1601-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0689" ref_id="CVE-2009-0689"/>
        <description>Updated kdelibs packages that fix one security issue are now available for
Red Hat Enterprise Linux 4 and 5.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
The kdelibs packages provide libraries for the K Desktop Environment (KDE).
A buffer overflow flaw was found in the kdelibs string to floating point
conversion routines. A web page containing malicious JavaScript could crash
Konqueror or, potentially, execute arbitrary code with the privileges of the
user running Konqueror. (CVE-2009-0689)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:37:33.366-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:43.655-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:38.308-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kdelibs-devel is earlier than 6:3.5.4-25.el5_4.1" test_ref="oval:org.mitre.oval:tst:140061"/>
            <criterion comment="kdelibs is earlier than 6:3.5.4-25.el5_4.1" test_ref="oval:org.mitre.oval:tst:140121"/>
            <criterion comment="kdelibs-apidocs is earlier than 6:3.5.4-25.el5_4.1" test_ref="oval:org.mitre.oval:tst:140212"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kdelibs is earlier than 6:3.3.1-17.el4_8.1" test_ref="oval:org.mitre.oval:tst:139744"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.3.1-17.el4_8.1" test_ref="oval:org.mitre.oval:tst:140188"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kdelibs is earlier than 6:3.5.4-25.el5.centos.1" test_ref="oval:org.mitre.oval:tst:140215"/>
            <criterion comment="kdelibs-apidocs is earlier than 6:3.5.4-25.el5.centos.1" test_ref="oval:org.mitre.oval:tst:140119"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.5.4-25.el5.centos.1" test_ref="oval:org.mitre.oval:tst:139912"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29359" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1238 -- dnsmasq security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>dnsmasq</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1238.html" ref_id="RHSA-2009:1238"/>
        <reference source="CESA-2009:1238" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-September/016119.html" ref_id="CESA-2009:1238-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2957" ref_id="CVE-2009-2957"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2958" ref_id="CVE-2009-2958"/>
        <description>An updated dnsmasq package that fixes two security issues is now available
for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
Dnsmasq is a lightweight and easy to configure DNS forwarder and DHCP
server.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:27.404-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:43.391-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:37.994-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="dnsmasq is earlier than 0:2.45-1.1.el5_3" test_ref="oval:org.mitre.oval:tst:140513"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29358" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1307 -- ecryptfs-utils security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>ecryptfs-utils</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1307.html" ref_id="RHSA-2009:1307"/>
        <reference source="CESA-2009:1307" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-September/016145.html" ref_id="CESA-2009:1307-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5188" ref_id="CVE-2008-5188"/>
        <description>Updated ecryptfs-utils packages that fix a security issue, various bugs,
and add enhancements are now available for Red Hat Enterprise Linux 5.
This update has been rated as having low security impact by the Red Hat
Security Response Team.
eCryptfs is a stacked, cryptographic file system. It is transparent to the
underlying file system and provides per-file granularity.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:19.499-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:43.254-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:37.830-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ecryptfs-utils-devel is earlier than 0:75-5.el5" test_ref="oval:org.mitre.oval:tst:140383"/>
          <criterion comment="ecryptfs-utils is earlier than 0:75-5.el5" test_ref="oval:org.mitre.oval:tst:140147"/>
          <criterion comment="ecryptfs-utils-gui is earlier than 0:75-5.el5" test_ref="oval:org.mitre.oval:tst:140283"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29354" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:1017 -- kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1017.html" ref_id="RHSA-2008:1017"/>
        <reference source="CESA-2008:1017" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-December/015497.html" ref_id="CESA-2008:1017-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3831" ref_id="CVE-2008-3831"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4554" ref_id="CVE-2008-4554"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4576" ref_id="CVE-2008-4576"/>
        <description>Updated kernel packages that resolve several security issues and fix
various bugs are now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The kernel packages contain the Linux kernel, the core of any Linux
operating system.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:18.804-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:42.998-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:37.516-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:140487"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:140455"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:139667"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:140586"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:140482"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:140171"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:140086"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:140019"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:140451"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:139690"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29350" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1287 -- openssh security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openssh</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1287.html" ref_id="RHSA-2009:1287"/>
        <reference source="CESA-2009:1287" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-September/016142.html" ref_id="CESA-2009:1287-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5161" ref_id="CVE-2008-5161"/>
        <description>Updated openssh packages that fix a security issue, a bug, and add
enhancements are now available for Red Hat Enterprise Linux 5.
This update has been rated as having low security impact by the Red Hat
Security Response Team.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:08.667-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:42.816-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:37.297-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssh is earlier than 0:4.3p2-36.el5" test_ref="oval:org.mitre.oval:tst:140711"/>
          <criterion comment="openssh-askpass is earlier than 0:4.3p2-36.el5" test_ref="oval:org.mitre.oval:tst:140866"/>
          <criterion comment="openssh-clients is earlier than 0:4.3p2-36.el5" test_ref="oval:org.mitre.oval:tst:140749"/>
          <criterion comment="openssh-server is earlier than 0:4.3p2-36.el5" test_ref="oval:org.mitre.oval:tst:140352"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29347" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1625 -- expat security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>expat</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1625.html" ref_id="RHSA-2009:1625"/>
        <reference source="CESA-2009:1625" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-December/016348.html" ref_id="CESA-2009:1625-CentOS 3"/>
        <reference source="CESA-2009:1625" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-December/016378.html" ref_id="CESA-2009:1625-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3560" ref_id="CVE-2009-3560"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3720" ref_id="CVE-2009-3720"/>
        <description>Updated expat packages that fix two security issues are now available for
Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Expat is a C library written by James Clark for parsing XML documents.
Two buffer over-read flaws were found in the way Expat handled malformed
UTF-8 sequences when processing XML files. A specially-crafted XML file
could cause applications using Expat to crash while parsing the file.
(CVE-2009-3560, CVE-2009-3720)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:37:37.697-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:42.589-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:36.984-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="expat-devel is earlier than 0:1.95.8-8.3.el5_4.2" test_ref="oval:org.mitre.oval:tst:140240"/>
            <criterion comment="expat is earlier than 0:1.95.8-8.3.el5_4.2" test_ref="oval:org.mitre.oval:tst:139271"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="expat is earlier than 0:1.95.5-6.2" test_ref="oval:org.mitre.oval:tst:139982"/>
            <criterion comment="expat-devel is earlier than 0:1.95.5-6.2" test_ref="oval:org.mitre.oval:tst:140268"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="expat is earlier than 0:1.95.7-4.el4_8.2" test_ref="oval:org.mitre.oval:tst:140080"/>
            <criterion comment="expat-devel is earlier than 0:1.95.7-4.el4_8.2" test_ref="oval:org.mitre.oval:tst:140152"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29345" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0338 -- php security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0338.html" ref_id="RHSA-2009:0338"/>
        <reference source="CESA-2009:0338" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-April/015725.html" ref_id="CESA-2009:0338-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3658" ref_id="CVE-2008-3658"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3660" ref_id="CVE-2008-3660"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5498" ref_id="CVE-2008-5498"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5557" ref_id="CVE-2008-5557"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5814" ref_id="CVE-2008-5814"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0754" ref_id="CVE-2009-0754"/>
        <description>Updated php packages that fix several security issues are now available for
Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:37">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:16.947-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:42.204-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:36.475-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="php is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:140066"/>
          <criterion comment="php-bcmath is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:140161"/>
          <criterion comment="php-cli is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:139468"/>
          <criterion comment="php-common is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:140198"/>
          <criterion comment="php-dba is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:140339"/>
          <criterion comment="php-devel is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:140079"/>
          <criterion comment="php-gd is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:139761"/>
          <criterion comment="php-imap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:140111"/>
          <criterion comment="php-ldap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:140227"/>
          <criterion comment="php-mbstring is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:140358"/>
          <criterion comment="php-mysql is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:140329"/>
          <criterion comment="php-ncurses is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:140154"/>
          <criterion comment="php-odbc is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:140127"/>
          <criterion comment="php-pdo is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:139406"/>
          <criterion comment="php-pgsql is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:139852"/>
          <criterion comment="php-snmp is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:140129"/>
          <criterion comment="php-soap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:139987"/>
          <criterion comment="php-xml is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:140323"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:140278"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29343" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0225 -- Red Hat Enterprise Linux 5.3 kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0225.html" ref_id="RHSA-2009:0225"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5029" ref_id="CVE-2008-5029"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5079" ref_id="CVE-2008-5079"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5182" ref_id="CVE-2008-5182"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5300" ref_id="CVE-2008-5300"/>
        <description>Updated kernel packages that fix three security issues, address several
hundred bugs and add numerous enhancements are now available as part of the
ongoing support and maintenance of Red Hat Enterprise Linux version 5. This
is the third regular update.
This update has been rated as having important security impact by the Red
Hat Security Response Team.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:03">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:21.048-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:41.903-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:36.157-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:140411"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:140200"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:140242"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:140466"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:140498"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:140236"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:140143"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:140403"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:140312"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:140249"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29342" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1674 -- firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1674.html" ref_id="RHSA-2009:1674"/>
        <reference source="CESA-2009:1674" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-December/016391.html" ref_id="CESA-2009:1674-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3979" ref_id="CVE-2009-3979"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3981" ref_id="CVE-2009-3981"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3983" ref_id="CVE-2009-3983"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3984" ref_id="CVE-2009-3984"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3985" ref_id="CVE-2009-3985"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3986" ref_id="CVE-2009-3986"/>
        <description>Updated firefox packages that fix several security issues are now available
for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:37:16.130-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:41.554-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:35.638-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:140229"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:140209"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:140040"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:3.0.16-1.el5_4" test_ref="oval:org.mitre.oval:tst:140068"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="firefox is earlier than 0:3.0.16-4.el4" test_ref="oval:org.mitre.oval:tst:140035"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:3.0.16-1.el5.centos" test_ref="oval:org.mitre.oval:tst:139751"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29340" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1472 -- xen security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1472.html" ref_id="RHSA-2009:1472"/>
        <reference source="CESA-2009:1472" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-October/016286.html" ref_id="CESA-2009:1472-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3525" ref_id="CVE-2009-3525"/>
        <description>Updated xen packages that fix a security issue and multiple bugs are now
available for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Xen is an open source virtualization framework. Virtualization allows users
to run guest operating systems in virtual machines on top of a host
operating system.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:01.983-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:41.296-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:35.330-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="xen-libs is earlier than 0:3.0.3-94.el5_4.1" test_ref="oval:org.mitre.oval:tst:140790"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xen is earlier than 0:3.0.3-94.el5_4.1" test_ref="oval:org.mitre.oval:tst:140576"/>
            <criterion comment="xen-devel is earlier than 0:3.0.3-94.el5_4.1" test_ref="oval:org.mitre.oval:tst:140783"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29339" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1066 -- squirrelmail security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>squirrelmail</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1066.html" ref_id="RHSA-2009:1066"/>
        <reference source="CESA-2009:1066" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-May/015945.html" ref_id="CESA-2009:1066-CentOS 3"/>
        <reference source="CESA-2009:1066" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-May/015947.html" ref_id="CESA-2009:1066-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1578" ref_id="CVE-2009-1578"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1579" ref_id="CVE-2009-1579"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1581" ref_id="CVE-2009-1581"/>
        <description>An updated squirrelmail package that fixes multiple security issues is now
available for Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
SquirrelMail is a standards-based webmail package written in PHP.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:17.037-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:40.964-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:35.053-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:141022"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-13.el3" test_ref="oval:org.mitre.oval:tst:140925"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el4_8.5" test_ref="oval:org.mitre.oval:tst:140607"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el5.centos.7" test_ref="oval:org.mitre.oval:tst:141047"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29334" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1430 -- firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>nspr</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1430.html" ref_id="RHSA-2009:1430"/>
        <reference source="CESA-2009:1430" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-September/016163.html" ref_id="CESA-2009:1430-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2654" ref_id="CVE-2009-2654"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3070" ref_id="CVE-2009-3070"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3071" ref_id="CVE-2009-3071"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3072" ref_id="CVE-2009-3072"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3074" ref_id="CVE-2009-3074"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3075" ref_id="CVE-2009-3075"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3076" ref_id="CVE-2009-3076"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3077" ref_id="CVE-2009-3077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3078" ref_id="CVE-2009-3078"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3079" ref_id="CVE-2009-3079"/>
        <description>Updated firefox packages that fix several security issues are now available
for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox. nspr provides the Netscape
Portable Runtime (NSPR).</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:47">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:15.037-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:40.171-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:34.319-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nspr-devel is earlier than 0:4.7.5-1.el5_4" test_ref="oval:org.mitre.oval:tst:140728"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:140668"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:139862"/>
            <criterion comment="nspr is earlier than 0:4.7.5-1.el5_4" test_ref="oval:org.mitre.oval:tst:139833"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:140834"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:3.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:140595"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:3.0.14-1.el4" test_ref="oval:org.mitre.oval:tst:140642"/>
            <criterion comment="nspr is earlier than 0:4.7.5-1.el4_8" test_ref="oval:org.mitre.oval:tst:140340"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.5-1.el4_8" test_ref="oval:org.mitre.oval:tst:140461"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:3.0.14-1.el5.centos" test_ref="oval:org.mitre.oval:tst:140504"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29331" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1451 -- freeradius security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>freeradius</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1451.html" ref_id="RHSA-2009:1451"/>
        <reference source="CESA-2009:1451" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-October/016228.html" ref_id="CESA-2009:1451-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3111" ref_id="CVE-2009-3111"/>
        <description>Updated freeradius packages that fix a security issue are now available for
Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
FreeRADIUS is a high-performance and highly configurable free Remote
Authentication Dial In User Service (RADIUS) server, designed to allow
centralized authentication and authorization for a network.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:46">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:16.108-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:40.041-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:34.151-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="freeradius is earlier than 0:1.1.3-1.5.el5_4" test_ref="oval:org.mitre.oval:tst:140537"/>
          <criterion comment="freeradius-mysql is earlier than 0:1.1.3-1.5.el5_4" test_ref="oval:org.mitre.oval:tst:140646"/>
          <criterion comment="freeradius-postgresql is earlier than 0:1.1.3-1.5.el5_4" test_ref="oval:org.mitre.oval:tst:140785"/>
          <criterion comment="freeradius-unixODBC is earlier than 0:1.1.3-1.5.el5_4" test_ref="oval:org.mitre.oval:tst:140356"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29320" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1428 -- xmlsec1 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>xmlsec1</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1428.html" ref_id="RHSA-2009:1428"/>
        <reference source="CESA-2009:1428" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-September/016161.html" ref_id="CESA-2009:1428-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0217" ref_id="CVE-2009-0217"/>
        <description>Updated xmlsec1 packages that fix one security issue are now available for
Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The XML Security Library is a C library based on libxml2 and OpenSSL. It
implements the XML Signature Syntax and Processing and XML Encryption
Syntax and Processing standards. HMAC is used for message authentication
using cryptographic hash functions. The HMAC algorithm allows the hash
output to be truncated (as documented in RFC 2104).</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:49">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:14.283-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:39.746-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:33.845-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xmlsec1-devel is earlier than 0:1.2.9-8.1.1" test_ref="oval:org.mitre.oval:tst:140664"/>
            <criterion comment="xmlsec1-gnutls-devel is earlier than 0:1.2.9-8.1.1" test_ref="oval:org.mitre.oval:tst:140781"/>
            <criterion comment="xmlsec1-nss-devel is earlier than 0:1.2.9-8.1.1" test_ref="oval:org.mitre.oval:tst:140757"/>
            <criterion comment="xmlsec1-openssl-devel is earlier than 0:1.2.9-8.1.1" test_ref="oval:org.mitre.oval:tst:140571"/>
            <criterion comment="xmlsec1 is earlier than 0:1.2.9-8.1.1" test_ref="oval:org.mitre.oval:tst:140817"/>
            <criterion comment="xmlsec1-gnutls is earlier than 0:1.2.9-8.1.1" test_ref="oval:org.mitre.oval:tst:139883"/>
            <criterion comment="xmlsec1-nss is earlier than 0:1.2.9-8.1.1" test_ref="oval:org.mitre.oval:tst:140592"/>
            <criterion comment="xmlsec1-openssl is earlier than 0:1.2.9-8.1.1" test_ref="oval:org.mitre.oval:tst:140808"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xmlsec1 is earlier than 0:1.2.6-3.1" test_ref="oval:org.mitre.oval:tst:140194"/>
            <criterion comment="xmlsec1-devel is earlier than 0:1.2.6-3.1" test_ref="oval:org.mitre.oval:tst:140647"/>
            <criterion comment="xmlsec1-openssl is earlier than 0:1.2.6-3.1" test_ref="oval:org.mitre.oval:tst:140559"/>
            <criterion comment="xmlsec1-openssl-devel is earlier than 0:1.2.6-3.1" test_ref="oval:org.mitre.oval:tst:140725"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29319" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0352 -- gstreamer-plugins-base security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gstreamer-plugins-base</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0352.html" ref_id="RHSA-2009:0352"/>
        <reference source="CESA-2009:0352" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-April/015741.html" ref_id="CESA-2009:0352-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0586" ref_id="CVE-2009-0586"/>
        <description>Updated gstreamer-plugins-base packages that fix a security issue are now
available for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
GStreamer is a streaming media framework based on graphs of filters which
operate on media data. GStreamer Base Plug-ins is a collection of
well-maintained base plug-ins.
An integer overflow flaw which caused a heap-based buffer overflow was
discovered in the Vorbis comment tags reader. An attacker could create a
carefully-crafted Vorbis file that would cause an application using
GStreamer to crash or, potentially, execute arbitrary code if opened by a
victim. (CVE-2009-0586)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:41">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:33.297-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:39.590-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:33.686-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gstreamer-plugins-base-devel is earlier than 0:0.10.20-3.0.1.el5_3" test_ref="oval:org.mitre.oval:tst:140069"/>
          <criterion comment="gstreamer-plugins-base is earlier than 0:0.10.20-3.0.1.el5_3" test_ref="oval:org.mitre.oval:tst:140365"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29317" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1579 -- httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1579.html" ref_id="RHSA-2009:1579"/>
        <reference source="CESA-2009:1579" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-November/016316.html" ref_id="CESA-2009:1579-CentOS 3"/>
        <reference source="CESA-2009:1579" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-November/016326.html" ref_id="CESA-2009:1579-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3094" ref_id="CVE-2009-3094"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3095" ref_id="CVE-2009-3095"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555" ref_id="CVE-2009-3555"/>
        <description>Updated httpd packages that fix multiple security issues are now available
for Red Hat Enterprise Linux 3 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The Apache HTTP Server is a popular Web server.
A flaw was found in the way the TLS/SSL (Transport Layer Security/Secure
Sockets Layer) protocols handle session renegotiation. A man-in-the-middle
attacker could use this flaw to prefix arbitrary plain text to a client's
session (for example, an HTTPS connection to a website). This could force
the server to process an attacker's request as if authenticated using the
victim's credentials. This update partially mitigates this flaw for SSL
sessions to HTTP servers using mod_ssl by rejecting client-requested
renegotiation. (CVE-2009-3555)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:34">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:37:46.409-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:39.334-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:33.392-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd-devel is earlier than 0:2.2.3-31.el5_4.2" test_ref="oval:org.mitre.oval:tst:140142"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-31.el5_4.2" test_ref="oval:org.mitre.oval:tst:140144"/>
            <criterion comment="httpd is earlier than 0:2.2.3-31.el5_4.2" test_ref="oval:org.mitre.oval:tst:140205"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-31.el5_4.2" test_ref="oval:org.mitre.oval:tst:140233"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd is earlier than 0:2.0.46-77.ent" test_ref="oval:org.mitre.oval:tst:140256"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.46-77.ent" test_ref="oval:org.mitre.oval:tst:140131"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.46-77.ent" test_ref="oval:org.mitre.oval:tst:139723"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd is earlier than 0:2.2.3-31.el5.centos.2" test_ref="oval:org.mitre.oval:tst:139927"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-31.el5.centos.2" test_ref="oval:org.mitre.oval:tst:139959"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-31.el5.centos.2" test_ref="oval:org.mitre.oval:tst:140230"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-31.el5.centos.2" test_ref="oval:org.mitre.oval:tst:140246"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29313" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0205 -- dovecot security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>dovecot</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0205.html" ref_id="RHSA-2009:0205"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4577" ref_id="CVE-2008-4577"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4870" ref_id="CVE-2008-4870"/>
        <description>An updated dovecot package that corrects two security flaws and various bugs
is now available for Red Hat Enterprise Linux 5.
This update has been rated as having low security impact by the Red Hat
Security Response Team.
Dovecot is an IMAP server for Linux and UNIX-like systems, primarily
written with security in mind.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:03">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:39:56.892-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:39.166-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:33.083-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="dovecot is earlier than 0:1.0.7-7.el5" test_ref="oval:org.mitre.oval:tst:140296"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29311" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1123 -- gstreamer-plugins-good security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gstreamer-plugins-good</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1123.html" ref_id="RHSA-2009:1123"/>
        <reference source="CESA-2009:1123" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-June/016005.html" ref_id="CESA-2009:1123-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1932" ref_id="CVE-2009-1932"/>
        <description>Updated gstreamer-plugins-good packages that fix multiple security issues
are now available for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
GStreamer is a streaming media framework, based on graphs of filters which
operate on media data. GStreamer Good Plug-ins is a collection of
well-supported, good quality GStreamer plug-ins.
Multiple integer overflow flaws, that could lead to a buffer overflow, were
found in the GStreamer Good Plug-ins PNG decoding handler. An attacker
could create a specially-crafted PNG file that would cause an application
using the GStreamer Good Plug-ins library to crash or, potentially, execute
arbitrary code as the user running the application when parsed.
(CVE-2009-1932)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:27.732-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:39.035-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:32.926-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gstreamer-plugins-good-devel is earlier than 0:0.10.9-1.el5_3.2" test_ref="oval:org.mitre.oval:tst:141073"/>
          <criterion comment="gstreamer-plugins-good is earlier than 0:0.10.9-1.el5_3.2" test_ref="oval:org.mitre.oval:tst:140782"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29310" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1513 -- cups security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1513.html" ref_id="RHSA-2009:1513"/>
        <reference source="CESA-2009:1513" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-October/016218.html" ref_id="CESA-2009:1513-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3608" ref_id="CVE-2009-3608"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3609" ref_id="CVE-2009-3609"/>
        <description>Updated cups packages that fix two security issues are now available for
Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:37">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:05.280-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:38.767-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:32.837-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="cups-devel is earlier than 1:1.3.7-11.el5_4.3" test_ref="oval:org.mitre.oval:tst:140070"/>
          <criterion comment="cups is earlier than 1:1.3.7-11.el5_4.3" test_ref="oval:org.mitre.oval:tst:140676"/>
          <criterion comment="cups-libs is earlier than 1:1.3.7-11.el5_4.3" test_ref="oval:org.mitre.oval:tst:140739"/>
          <criterion comment="cups-lpd is earlier than 1:1.3.7-11.el5_4.3" test_ref="oval:org.mitre.oval:tst:140610"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29308" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:1001 -- tog-pegasus security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>tog-pegasus</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1001.html" ref_id="RHSA-2008:1001"/>
        <reference source="CESA-2008:1001" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-November/015455.html" ref_id="CESA-2008:1001-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4313" ref_id="CVE-2008-4313"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4315" ref_id="CVE-2008-4315"/>
        <description>Updated tog-pegasus packages that fix security issues are now available
for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team. 
The tog-pegasus packages provide OpenPegasus Web-Based Enterprise
Management (WBEM) services. WBEM is a platform and resource independent
Distributed Management Task Force (DMTF) standard that defines a common
information model and communication protocol for monitoring and controlling
resources.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:25.842-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:38.590-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:32.650-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tog-pegasus is earlier than 2:2.7.0-2.el5_2.1" test_ref="oval:org.mitre.oval:tst:140722"/>
          <criterion comment="tog-pegasus-devel is earlier than 2:2.7.0-2.el5_2.1" test_ref="oval:org.mitre.oval:tst:140289"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29306" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0988 -- libxml2 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 2</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0988.html" ref_id="RHSA-2008:0988"/>
        <reference source="CESA-2008:0988" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-November/015412.html" ref_id="CESA-2008:0988-CentOS 5"/>
        <reference source="CESA-2008:0988" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-November/015414.html" ref_id="CESA-2008:0988-CentOS 3"/>
        <reference source="CESA-2008:0988" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-November/015436.html" ref_id="CESA-2008:0988-CentOS 2"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4225" ref_id="CVE-2008-4225"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4226" ref_id="CVE-2008-4226"/>
        <description>Updated libxml2 packages that fix security issues are now available for
Red Hat Enterprise Linux 2.1, 3, 4, and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
libxml2 is a library for parsing and manipulating XML files. It includes
support for reading, modifying, and writing XML and HTML files.
An integer overflow flaw causing a heap-based buffer overflow was found in
the libxml2 XML parser. If an application linked against libxml2 processed
untrusted, malformed XML content, it could cause the application to crash
or, possibly, execute arbitrary code. (CVE-2008-4226)
A denial of service flaw was discovered in the libxml2 XML parser. If an
application linked against libxml2 processed untrusted, malformed XML
content, it could cause the application to enter an infinite loop.
(CVE-2008-4225)
Red Hat would like to thank Drew Yao of the Apple Product Security team for
reporting these issues.
Users of libxml2 are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:04.155-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:38.353-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:32.428-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.7" test_ref="oval:org.mitre.oval:tst:139787"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.2.7" test_ref="oval:org.mitre.oval:tst:140712"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.2.7" test_ref="oval:org.mitre.oval:tst:140707"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.5.10-14" test_ref="oval:org.mitre.oval:tst:140507"/>
            <criterion comment="libxml2-devel is earlier than 0:2.5.10-14" test_ref="oval:org.mitre.oval:tst:140734"/>
            <criterion comment="libxml2-python is earlier than 0:2.5.10-14" test_ref="oval:org.mitre.oval:tst:140330"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.6.16-12.6" test_ref="oval:org.mitre.oval:tst:140442"/>
            <criterion comment="libxml2-devel is earlier than 0:2.6.16-12.6" test_ref="oval:org.mitre.oval:tst:140671"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.16-12.6" test_ref="oval:org.mitre.oval:tst:140444"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29301" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1127 -- kdelibs security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>kdelibs</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1127.html" ref_id="RHSA-2009:1127"/>
        <reference source="CESA-2009:1127" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-June/016007.html" ref_id="CESA-2009:1127-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1687" ref_id="CVE-2009-1687"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1690" ref_id="CVE-2009-1690"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1698" ref_id="CVE-2009-1698"/>
        <description>Updated kdelibs packages that fix multiple security issues are now
available for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
The kdelibs packages provide libraries for the K Desktop Environment (KDE).</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:26.089-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:38.117-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:32.161-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kdelibs-devel is earlier than 6:3.5.4-22.el5_3" test_ref="oval:org.mitre.oval:tst:140490"/>
            <criterion comment="kdelibs is earlier than 6:3.5.4-22.el5_3" test_ref="oval:org.mitre.oval:tst:140922"/>
            <criterion comment="kdelibs-apidocs is earlier than 6:3.5.4-22.el5_3" test_ref="oval:org.mitre.oval:tst:140906"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kdelibs is earlier than 6:3.3.1-14.el4" test_ref="oval:org.mitre.oval:tst:140955"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.3.1-14.el4" test_ref="oval:org.mitre.oval:tst:140547"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kdelibs is earlier than 6:3.5.4-22.el5.centos" test_ref="oval:org.mitre.oval:tst:141054"/>
            <criterion comment="kdelibs-apidocs is earlier than 6:3.5.4-22.el5.centos" test_ref="oval:org.mitre.oval:tst:140980"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.5.4-22.el5.centos" test_ref="oval:org.mitre.oval:tst:140970"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29300" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0011 -- lcms security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>lcms</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0011.html" ref_id="RHSA-2009:0011"/>
        <reference source="CESA-2009:0011" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-January/015528.html" ref_id="CESA-2009:0011-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5316" ref_id="CVE-2008-5316"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5317" ref_id="CVE-2008-5317"/>
        <description>Updated lcms packages that resolve several security issues are now
available for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:07.789-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:37.909-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:31.961-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="lcms-devel is earlier than 0:1.15-1.2.2.el5_2.2" test_ref="oval:org.mitre.oval:tst:140534"/>
          <criterion comment="lcms is earlier than 0:1.15-1.2.2.el5_2.2" test_ref="oval:org.mitre.oval:tst:140163"/>
          <criterion comment="python-lcms is earlier than 0:1.15-1.2.2.el5_2.2" test_ref="oval:org.mitre.oval:tst:140585"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29299" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1107 -- apr-util security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>apr-util</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1107.html" ref_id="RHSA-2009:1107"/>
        <reference source="CESA-2009:1107" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-June/015983.html" ref_id="CESA-2009:1107-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0023" ref_id="CVE-2009-0023"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1955" ref_id="CVE-2009-1955"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1956" ref_id="CVE-2009-1956"/>
        <description>Updated apr-util packages that fix multiple security issues are now
available for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
apr-util is a utility library used with the Apache Portable Runtime (APR).
It aims to provide a free library of C data structures and routines. This
library contains additional utility interfaces for APR; including support
for XML, LDAP, database interfaces, URI parsing, and more.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:18.020-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:37.564-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:31.712-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="apr-util-devel is earlier than 0:1.2.7-7.el5_3.1" test_ref="oval:org.mitre.oval:tst:140961"/>
            <criterion comment="apr-util is earlier than 0:1.2.7-7.el5_3.1" test_ref="oval:org.mitre.oval:tst:140901"/>
            <criterion comment="apr-util-docs is earlier than 0:1.2.7-7.el5_3.1" test_ref="oval:org.mitre.oval:tst:140345"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="apr-util is earlier than 0:0.9.4-22.el4_8.1" test_ref="oval:org.mitre.oval:tst:141065"/>
            <criterion comment="apr-util-devel is earlier than 0:0.9.4-22.el4_8.1" test_ref="oval:org.mitre.oval:tst:140751"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29294" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1176 -- python security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>python</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1176.html" ref_id="RHSA-2009:1176"/>
        <reference source="CESA-2009:1176" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-July/016050.html" ref_id="CESA-2009:1176-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2052" ref_id="CVE-2007-2052"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4965" ref_id="CVE-2007-4965"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1721" ref_id="CVE-2008-1721"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1887" ref_id="CVE-2008-1887"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2315" ref_id="CVE-2008-2315"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3142" ref_id="CVE-2008-3142"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3143" ref_id="CVE-2008-3143"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3144" ref_id="CVE-2008-3144"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4864" ref_id="CVE-2008-4864"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5031" ref_id="CVE-2008-5031"/>
        <description>Updated python packages that fix multiple security issues are now available
for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Python is an interpreted, interactive, object-oriented programming
language.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:22.203-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:36.990-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:31.140-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="python-devel is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:140279"/>
          <criterion comment="python is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:140849"/>
          <criterion comment="python-tools is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:140390"/>
          <criterion comment="tkinter is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:140670"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29289" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0967 -- httpd security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 3</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0967.html" ref_id="RHSA-2008:0967"/>
        <reference source="CESA-2008:0967" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-November/015389.html" ref_id="CESA-2008:0967-CentOS 5"/>
        <reference source="CESA-2008:0967" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-November/015393.html" ref_id="CESA-2008:0967-CentOS 3"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2364" ref_id="CVE-2008-2364"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2939" ref_id="CVE-2008-2939"/>
        <description>Updated httpd packages that resolve several security issues and fix a bug
are now available for Red Hat Enterprise Linux 3, 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The Apache HTTP Server is a popular Web server.
A flaw was found in the mod_proxy Apache module. An attacker in control of
a Web server to which requests were being proxied could have caused a
limited denial of service due to CPU consumption and stack exhaustion.
(CVE-2008-2364)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:24.044-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:36.754-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:30.892-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd-devel is earlier than 0:2.2.3-11.el5_2.4" test_ref="oval:org.mitre.oval:tst:140735"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-11.el5_2.4" test_ref="oval:org.mitre.oval:tst:140774"/>
            <criterion comment="httpd is earlier than 0:2.2.3-11.el5_2.4" test_ref="oval:org.mitre.oval:tst:140397"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-11.el5_2.4" test_ref="oval:org.mitre.oval:tst:140591"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd is earlier than 0:2.0.46-71.ent" test_ref="oval:org.mitre.oval:tst:140159"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.46-71.ent" test_ref="oval:org.mitre.oval:tst:140741"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.46-71.ent" test_ref="oval:org.mitre.oval:tst:140593"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:140553"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:140328"/>
            <criterion comment="httpd-manual is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:140744"/>
            <criterion comment="httpd-suexec is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:140222"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:140662"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd is earlier than 0:2.2.3-11.el5.centos.4" test_ref="oval:org.mitre.oval:tst:140633"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-11.el5.centos.4" test_ref="oval:org.mitre.oval:tst:140396"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-11.el5.centos.4" test_ref="oval:org.mitre.oval:tst:140761"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-11.el5.centos.4" test_ref="oval:org.mitre.oval:tst:140630"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29288" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0008 -- dbus security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>dbus</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0008.html" ref_id="RHSA-2009:0008"/>
        <reference source="CESA-2009:0008" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-January/015530.html" ref_id="CESA-2009:0008-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3834" ref_id="CVE-2008-3834"/>
        <description>Updated dbus packages that fix a security issue are now available for Red
Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
D-Bus is a system for sending messages between applications. It is used for
the system-wide message bus service and as a per-user-login-session
messaging facility.
A denial-of-service flaw was discovered in the system for sending messages
between applications. A local user could send a message with a malformed
signature to the bus causing the bus (and, consequently, any process using
libdbus to receive messages) to abort. (CVE-2008-3834)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:13.996-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:36.570-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:30.764-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dbus-devel is earlier than 0:1.0.0-7.el5_2.1" test_ref="oval:org.mitre.oval:tst:140162"/>
          <criterion comment="dbus is earlier than 0:1.0.0-7.el5_2.1" test_ref="oval:org.mitre.oval:tst:140060"/>
          <criterion comment="dbus-x11 is earlier than 0:1.0.0-7.el5_2.1" test_ref="oval:org.mitre.oval:tst:140582"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29286" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0444 -- giflib security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>giflib</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0444.html" ref_id="RHSA-2009:0444"/>
        <reference source="CESA-2009:0444" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-April/015828.html" ref_id="CESA-2009:0444-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2974" ref_id="CVE-2005-2974"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3350" ref_id="CVE-2005-3350"/>
        <description>Updated giflib packages that fix several security issues are now available
for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The giflib packages contain a shared library of functions for loading and
saving GIF image files. This library is API and ABI compatible with
libungif, the library that supported uncompressed GIF image files while the
Unisys LZW patent was in effect.
Several flaws were discovered in the way giflib decodes GIF images. An
attacker could create a carefully crafted GIF image that could cause an
application using giflib to crash or, possibly, execute arbitrary code when
opened by a victim. (CVE-2005-2974, CVE-2005-3350)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:30">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:32.056-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:36.337-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:30.584-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="giflib-devel is earlier than 0:4.1.3-7.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:140026"/>
          <criterion comment="giflib is earlier than 0:4.1.3-7.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:140120"/>
          <criterion comment="giflib-utils is earlier than 0:4.1.3-7.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:139609"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29283" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1646 -- libtool security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>libtool</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1646.html" ref_id="RHSA-2009:1646"/>
        <reference source="CESA-2009:1646" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-December/016354.html" ref_id="CESA-2009:1646-CentOS 3"/>
        <reference source="CESA-2009:1646" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-December/016383.html" ref_id="CESA-2009:1646-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3736" ref_id="CVE-2009-3736"/>
        <description>Updated libtool packages that fix one security issue are now available for
Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:37:45.732-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:36.138-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:30.421-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtool is earlier than 0:1.5.22-7.el5_4" test_ref="oval:org.mitre.oval:tst:140220"/>
            <criterion comment="libtool-ltdl-devel is earlier than 0:1.5.22-7.el5_4" test_ref="oval:org.mitre.oval:tst:139736"/>
            <criterion comment="libtool-ltdl is earlier than 0:1.5.22-7.el5_4" test_ref="oval:org.mitre.oval:tst:140027"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtool is earlier than 0:1.4.3-7" test_ref="oval:org.mitre.oval:tst:140149"/>
            <criterion comment="libtool-libs is earlier than 0:1.4.3-7" test_ref="oval:org.mitre.oval:tst:140110"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtool is earlier than 0:1.5.6-5.el4_8" test_ref="oval:org.mitre.oval:tst:139520"/>
            <criterion comment="libtool-libs is earlier than 0:1.5.6-5.el4_8" test_ref="oval:org.mitre.oval:tst:139847"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29281" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1232 -- gnutls security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1232.html" ref_id="RHSA-2009:1232"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2730" ref_id="CVE-2009-2730"/>
        <description>Updated gnutls packages that fix a security issue are now available for Red
Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:11.759-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:35.961-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:30.285-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="gnutls-devel is earlier than 0:1.4.1-3.el5_3.5" test_ref="oval:org.mitre.oval:tst:140878"/>
            <criterion comment="gnutls is earlier than 0:1.4.1-3.el5_3.5" test_ref="oval:org.mitre.oval:tst:140234"/>
            <criterion comment="gnutls-utils is earlier than 0:1.4.1-3.el5_3.5" test_ref="oval:org.mitre.oval:tst:140510"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="gnutls is earlier than 0:1.0.20-4.el4_8.3" test_ref="oval:org.mitre.oval:tst:140864"/>
            <criterion comment="gnutls-devel is earlier than 0:1.0.20-4.el4_8.3" test_ref="oval:org.mitre.oval:tst:140842"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29277" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0377 -- java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0377.html" ref_id="RHSA-2009:0377"/>
        <reference source="CESA-2009:0377" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-April/015734.html" ref_id="CESA-2009:0377-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2426" ref_id="CVE-2006-2426"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0581" ref_id="CVE-2009-0581"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0723" ref_id="CVE-2009-0723"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0733" ref_id="CVE-2009-0733"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0793" ref_id="CVE-2009-0793"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1093" ref_id="CVE-2009-1093"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1094" ref_id="CVE-2009-1094"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1095" ref_id="CVE-2009-1095"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1096" ref_id="CVE-2009-1096"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1097" ref_id="CVE-2009-1097"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1098" ref_id="CVE-2009-1098"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1101" ref_id="CVE-2009-1101"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1102" ref_id="CVE-2009-1102"/>
        <description>Updated java-1.6.0-openjdk packages that fix several security issues are
now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit. The Java Runtime Environment (JRE)
contains the software and tools that users need to run applications written
using the Java programming language.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:37">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:07.136-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:35.217-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:29.205-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:140367"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:139843"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:140304"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:139386"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:140337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29276" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0421 -- ghostscript security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>ghostscript</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0421.html" ref_id="RHSA-2009:0421"/>
        <reference source="CESA-2009:0421" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-April/015790.html" ref_id="CESA-2009:0421-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6725" ref_id="CVE-2007-6725"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6679" ref_id="CVE-2008-6679"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0196" ref_id="CVE-2009-0196"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0792" ref_id="CVE-2009-0792"/>
        <description>Updated ghostscript packages that fix multiple security issues are now
available for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Ghostscript is a set of software that provides a PostScript interpreter, a
set of C procedures (the Ghostscript library, which implements the graphics
capabilities in the PostScript language) and an interpreter for Portable
Document Format (PDF) files.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:33">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:10.301-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:34.924-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:28.862-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ghostscript-devel is earlier than 0:8.15.2-9.4.el5_3.7" test_ref="oval:org.mitre.oval:tst:140267"/>
          <criterion comment="ghostscript is earlier than 0:8.15.2-9.4.el5_3.7" test_ref="oval:org.mitre.oval:tst:140299"/>
          <criterion comment="ghostscript-gtk is earlier than 0:8.15.2-9.4.el5_3.7" test_ref="oval:org.mitre.oval:tst:139829"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29275" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1549 -- wget security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>wget</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1549.html" ref_id="RHSA-2009:1549"/>
        <reference source="CESA-2009:1549" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-November/016298.html" ref_id="CESA-2009:1549-CentOS 3"/>
        <reference source="CESA-2009:1549" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-November/016324.html" ref_id="CESA-2009:1549-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3490" ref_id="CVE-2009-3490"/>
        <description>An updated wget package that fixes a security issue is now available for
Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
GNU Wget is a file retrieval utility that can use HTTP, HTTPS, and FTP.
Daniel Stenberg reported that Wget is affected by the previously published
null prefix attack, caused by incorrect handling of NULL characters in
X.509 certificates. If an attacker is able to get a carefully-crafted
certificate signed by a trusted Certificate Authority, the attacker could
use the certificate during a man-in-the-middle attack and potentially
confuse Wget into accepting it by mistake. (CVE-2009-3490)
Wget users should upgrade to this updated package, which contains a
backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:33.736-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:34.765-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:28.698-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="wget is earlier than 0:1.10.2-0.30E.1" test_ref="oval:org.mitre.oval:tst:140754"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="wget is earlier than 0:1.10.2-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:140710"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="wget is earlier than 0:1.11.4-2.el5_4.1" test_ref="oval:org.mitre.oval:tst:140459"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29271" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1470 -- openssh security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openssh</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1470.html" ref_id="RHSA-2009:1470"/>
        <reference source="CESA-2009:1470" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-October/016264.html" ref_id="CESA-2009:1470-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2904" ref_id="CVE-2009-2904"/>
        <description>Updated openssh packages that fix a security issue are now available for
Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:41">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:00.504-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:34.643-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:28.555-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssh is earlier than 0:4.3p2-36.el5_4.2" test_ref="oval:org.mitre.oval:tst:140587"/>
          <criterion comment="openssh-askpass is earlier than 0:4.3p2-36.el5_4.2" test_ref="oval:org.mitre.oval:tst:140706"/>
          <criterion comment="openssh-clients is earlier than 0:4.3p2-36.el5_4.2" test_ref="oval:org.mitre.oval:tst:140556"/>
          <criterion comment="openssh-server is earlier than 0:4.3p2-36.el5_4.2" test_ref="oval:org.mitre.oval:tst:140527"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29270" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1452 -- neon security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>neon</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1452.html" ref_id="RHSA-2009:1452"/>
        <reference source="CESA-2009:1452" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-October/016252.html" ref_id="CESA-2009:1452-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2473" ref_id="CVE-2009-2473"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2474" ref_id="CVE-2009-2474"/>
        <description>Updated neon packages that fix two security issues are now available for
Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
neon is an HTTP and WebDAV client library, with a C interface. It provides
a high-level interface to HTTP and WebDAV methods along with a low-level
interface for HTTP request handling. neon supports persistent connections,
proxy servers, basic, digest and Kerberos authentication, and has complete
SSL support.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:46">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:04.189-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:34.466-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:28.355-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="neon-devel is earlier than 0:0.25.5-10.el5_4.1" test_ref="oval:org.mitre.oval:tst:140693"/>
            <criterion comment="neon is earlier than 0:0.25.5-10.el5_4.1" test_ref="oval:org.mitre.oval:tst:140446"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="neon is earlier than 0:0.24.7-4.el4_8.2" test_ref="oval:org.mitre.oval:tst:140540"/>
            <criterion comment="neon-devel is earlier than 0:0.24.7-4.el4_8.2" test_ref="oval:org.mitre.oval:tst:140645"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29269" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1548 -- kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1548.html" ref_id="RHSA-2009:1548"/>
        <reference source="CESA-2009:1548" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-November/016304.html" ref_id="CESA-2009:1548-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2695" ref_id="CVE-2009-2695"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2908" ref_id="CVE-2009-2908"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3228" ref_id="CVE-2009-3228"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3286" ref_id="CVE-2009-3286"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3547" ref_id="CVE-2009-3547"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3613" ref_id="CVE-2009-3613"/>
        <description>Updated kernel packages that fix multiple security issues and several bugs
are now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The kernel packages contain the Linux kernel, the core of any Linux
operating system.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:30.138-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:34.122-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:27.944-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:140226"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:140327"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:140318"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:140583"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:140694"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:140772"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:140663"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:140627"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:139798"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:140472"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29267" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0436 -- firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0436.html" ref_id="RHSA-2009:0436"/>
        <reference source="CESA-2009:0436" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-April/015824.html" ref_id="CESA-2009:0436-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0652" ref_id="CVE-2009-0652"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1302" ref_id="CVE-2009-1302"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1303" ref_id="CVE-2009-1303"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1304" ref_id="CVE-2009-1304"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1305" ref_id="CVE-2009-1305"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1306" ref_id="CVE-2009-1306"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1307" ref_id="CVE-2009-1307"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1308" ref_id="CVE-2009-1308"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1309" ref_id="CVE-2009-1309"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1310" ref_id="CVE-2009-1310"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1311" ref_id="CVE-2009-1311"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1312" ref_id="CVE-2009-1312"/>
        <description>Updated firefox packages that fix several security issues are now available
for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-1302, CVE-2009-1303, CVE-2009-1304, CVE-2009-1305)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:31">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:39:58.584-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:33.683-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:27.489-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:140302"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:140074"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:140158"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:3.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:140175"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="firefox is earlier than 0:3.0.9-1.el4" test_ref="oval:org.mitre.oval:tst:140155"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:3.0.9-1.el5.centos" test_ref="oval:org.mitre.oval:tst:140223"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29266" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1648 -- ntp security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>ntp</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1648.html" ref_id="RHSA-2009:1648"/>
        <reference source="CESA-2009:1648" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-December/016406.html" ref_id="CESA-2009:1648-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3563" ref_id="CVE-2009-3563"/>
        <description>An updated ntp package that fixes a security issue is now available for Red
Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:37:34.444-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:33.546-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:27.300-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="ntp is earlier than 0:4.2.0.a.20040617-8.el4_8.1" test_ref="oval:org.mitre.oval:tst:139946"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="ntp is earlier than 0:4.2.2p1-9.el5_4.1" test_ref="oval:org.mitre.oval:tst:139902"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="ntp is earlier than 0:4.2.2p1-9.el5.centos.2.1" test_ref="oval:org.mitre.oval:tst:139265"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29265" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0957 -- kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0957.html" ref_id="RHSA-2008:0957"/>
        <reference source="CESA-2008:0957" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-November/015369.html" ref_id="CESA-2008:0957-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5755" ref_id="CVE-2006-5755"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5907" ref_id="CVE-2007-5907"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2372" ref_id="CVE-2008-2372"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3276" ref_id="CVE-2008-3276"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3527" ref_id="CVE-2008-3527"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3833" ref_id="CVE-2008-3833"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4210" ref_id="CVE-2008-4210"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4302" ref_id="CVE-2008-4302"/>
        <description>Updated kernel packages that resolve several security issues and fix
various bugs are now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The original packages distributed with this errata had a bug which
prevented the Xen kernel booting on older hardware. We have updated the
packages to correct this bug.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:21.746-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:32.902-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:26.785-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:140484"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:139934"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:140544"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:140437"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:140720"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:140688"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:140491"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:140495"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:140743"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:140703"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel is earlier than 0:2.6.18-92.1.17.el5" test_ref="oval:org.mitre.oval:tst:139968"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-92.1.17.el5" test_ref="oval:org.mitre.oval:tst:140260"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.17.el5" test_ref="oval:org.mitre.oval:tst:140759"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-92.1.17.el5" test_ref="oval:org.mitre.oval:tst:140603"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-92.1.17.el5" test_ref="oval:org.mitre.oval:tst:140546"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-92.1.17.el5" test_ref="oval:org.mitre.oval:tst:140612"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-92.1.17.el5" test_ref="oval:org.mitre.oval:tst:140536"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.17.el5" test_ref="oval:org.mitre.oval:tst:140655"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-92.1.17.el5" test_ref="oval:org.mitre.oval:tst:140682"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.17.el5" test_ref="oval:org.mitre.oval:tst:140617"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29264" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1529 -- samba security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1529.html" ref_id="RHSA-2009:1529"/>
        <reference source="CESA-2009:1529" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-October/016276.html" ref_id="CESA-2009:1529-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1888" ref_id="CVE-2009-1888"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2813" ref_id="CVE-2009-2813"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906" ref_id="CVE-2009-2906"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2948" ref_id="CVE-2009-2948"/>
        <description>Updated samba packages that fix multiple security issues are now available
for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Samba is a suite of programs used by machines to share files, printers, and
other information.
A denial of service flaw was found in the Samba smbd daemon. An
authenticated, remote user could send a specially-crafted response that
would cause an smbd child process to enter an infinite loop. An
authenticated, remote user could use this flaw to exhaust system resources
by opening multiple CIFS sessions. (CVE-2009-2906)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:13.616-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:32.517-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:26.450-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:140058"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:140629"/>
            <criterion comment="samba-common is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:139800"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:140319"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:139908"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:140064"/>
            <criterion comment="samba-common is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:140460"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:140564"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29263" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1642 -- acpid security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>acpid</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1642.html" ref_id="RHSA-2009:1642"/>
        <reference source="CESA-2009:1642" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-December/016380.html" ref_id="CESA-2009:1642-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4033" ref_id="CVE-2009-4033"/>
        <description>An updated acpid package that fixes one security issue is now available for
Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:37:39.165-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:32.397-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:26.274-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="acpid is earlier than 0:1.0.4-9.el5_4.1" test_ref="oval:org.mitre.oval:tst:140092"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29262" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0361 -- NetworkManager security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>NetworkManager</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0361.html" ref_id="RHSA-2009:0361"/>
        <reference source="CESA-2009:0361" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-April/015742.html" ref_id="CESA-2009:0361-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0365" ref_id="CVE-2009-0365"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0578" ref_id="CVE-2009-0578"/>
        <description>Updated NetworkManager packages that fix two security issues are now
available for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
NetworkManager is a network link manager that attempts to keep a wired or
wireless network connection active at all times.
An information disclosure flaw was found in NetworkManager's D-Bus
interface. A local attacker could leverage this flaw to discover sensitive
information, such as network connection passwords and pre-shared keys.
(CVE-2009-0365)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:52">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:27.810-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:32.212-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:26.073-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="NetworkManager-devel is earlier than 1:0.7.0-4.el5_3" test_ref="oval:org.mitre.oval:tst:140088"/>
          <criterion comment="NetworkManager-glib-devel is earlier than 1:0.7.0-4.el5_3" test_ref="oval:org.mitre.oval:tst:140376"/>
          <criterion comment="NetworkManager is earlier than 1:0.7.0-4.el5_3" test_ref="oval:org.mitre.oval:tst:140366"/>
          <criterion comment="NetworkManager-glib is earlier than 1:0.7.0-4.el5_3" test_ref="oval:org.mitre.oval:tst:139966"/>
          <criterion comment="NetworkManager-gnome is earlier than 1:0.7.0-4.el5_3" test_ref="oval:org.mitre.oval:tst:140085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29261" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0013 -- avahi security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>avahi</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0013.html" ref_id="RHSA-2009:0013"/>
        <reference source="CESA-2009:0013" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-January/015543.html" ref_id="CESA-2009:0013-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5081" ref_id="CVE-2008-5081"/>
        <description>Updated avahi packages that fix a security issue are now available for Red
Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Avahi is an implementation of the DNS Service Discovery and Multicast DNS
specifications for Zeroconf Networking. It facilitates service discovery on
a local network. Avahi and Avahi-aware applications allow you to plug your
computer into a network and, with no configuration, view other people to
chat with, see printers to print to, and find shared files on other computers.
Hugo Dias discovered a denial of service flaw in avahi-daemon. A remote
attacker on the same local area network (LAN) could send a
specially-crafted mDNS (Multicast DNS) packet that would cause avahi-daemon
to exit unexpectedly due to a failed assertion check. (CVE-2008-5081)
All users are advised to upgrade to these updated packages, which contain a
backported patch which resolves this issue. After installing the update,
avahi-daemon will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:04.645-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:32.068-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:25.893-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="avahi-compat-howl-devel is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:140407"/>
          <criterion comment="avahi-compat-libdns_sd-devel is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:140416"/>
          <criterion comment="avahi-devel is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:140515"/>
          <criterion comment="avahi-glib-devel is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:140409"/>
          <criterion comment="avahi-qt3-devel is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:140297"/>
          <criterion comment="avahi is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:140073"/>
          <criterion comment="avahi-compat-howl is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:140334"/>
          <criterion comment="avahi-compat-libdns_sd is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:140321"/>
          <criterion comment="avahi-glib is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:140247"/>
          <criterion comment="avahi-qt3 is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:140389"/>
          <criterion comment="avahi-tools is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:140423"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29259" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1364 -- gdm security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gdm</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1364.html" ref_id="RHSA-2009:1364"/>
        <reference source="CESA-2009:1364" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-September/016157.html" ref_id="CESA-2009:1364-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2697" ref_id="CVE-2009-2697"/>
        <description>Updated gdm packages that fix a security issue and several bugs are now
available for Red Hat Enterprise Linux 5.
This update has been rated as having low security impact by the Red Hat
Security Response Team.
The GNOME Display Manager (GDM) is a configurable re-implementation of XDM,
the X Display Manager. GDM allows you to log in to your system with the X
Window System running, and supports running several different X sessions on
your local machine at the same time.
A flaw was found in the way the gdm package was built. The gdm package was
missing TCP wrappers support, which could result in an administrator
believing they had access restrictions enabled when they did not.
(CVE-2009-2697)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:36.121-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:31.929-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:25.734-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="gdm is earlier than 1:2.16.0-56.el5" test_ref="oval:org.mitre.oval:tst:140634"/>
            <criterion comment="gdm-docs is earlier than 1:2.16.0-56.el5" test_ref="oval:org.mitre.oval:tst:140213"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="gdm is earlier than 1:2.16.0-56.el5.centos" test_ref="oval:org.mitre.oval:tst:140891"/>
            <criterion comment="gdm-docs is earlier than 1:2.16.0-56.el5.centos" test_ref="oval:org.mitre.oval:tst:140886"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29258" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1140 -- ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1140.html" ref_id="RHSA-2009:1140"/>
        <reference source="CESA-2009:1140" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-July/016025.html" ref_id="CESA-2009:1140-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1558" ref_id="CVE-2007-1558"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0642" ref_id="CVE-2009-0642"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1904" ref_id="CVE-2009-1904"/>
        <description>Updated ruby packages that fix multiple security issues are now available
for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:29.230-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:31.668-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:25.373-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:140762"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:140989"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:140046"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:140885"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:141037"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:140665"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:140968"/>
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:140095"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:140930"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:140913"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:140542"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:140972"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:140833"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:140994"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:140486"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:141046"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29255" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0581 -- bluez-libs and bluez-utils security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>bluez-libs</product>
          <product>bluez-utils</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0581.html" ref_id="RHSA-2008:0581"/>
        <reference source="CESA-2008:0581" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-July/015116.html" ref_id="CESA-2008:0581-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2374" ref_id="CVE-2008-2374"/>
        <description>Updated bluez-libs and bluez-utils packages that fix a security flaw are
now available for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The bluez-libs package contains libraries for use in Bluetooth
applications. The bluez-utils package contains Bluetooth daemons and utilities.
An input validation flaw was found in the Bluetooth Session Description
Protocol (SDP) packet parser used by the Bluez Bluetooth utilities. A
Bluetooth device with an already-established trust relationship, or a local
user registering a service record via a UNIX reg; socket or D-Bus interface,
could cause a crash, or possibly execute arbitrary code with privileges of
the hcid daemon. (CVE-2008-2374)
Users of bluez-libs and bluez-utils are advised to upgrade to these updated
packages, which contains a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:19.056-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:31.532-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:25.180-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bluez-libs-devel is earlier than 0:3.7-1.1" test_ref="oval:org.mitre.oval:tst:139117"/>
            <criterion comment="bluez-libs is earlier than 0:3.7-1.1" test_ref="oval:org.mitre.oval:tst:138482"/>
            <criterion comment="bluez-utils is earlier than 0:3.7-2.2" test_ref="oval:org.mitre.oval:tst:138707"/>
            <criterion comment="bluez-utils-cups is earlier than 0:3.7-2.2" test_ref="oval:org.mitre.oval:tst:139181"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bluez-libs is earlier than 0:2.10-3" test_ref="oval:org.mitre.oval:tst:139259"/>
            <criterion comment="bluez-libs-devel is earlier than 0:2.10-3" test_ref="oval:org.mitre.oval:tst:139237"/>
            <criterion comment="bluez-utils is earlier than 0:2.10-2.4" test_ref="oval:org.mitre.oval:tst:139067"/>
            <criterion comment="bluez-utils-cups is earlier than 0:2.10-2.4" test_ref="oval:org.mitre.oval:tst:139020"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29254" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1102 -- cscope security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>cscope</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1102.html" ref_id="RHSA-2009:1102"/>
        <reference source="CESA-2009:1102" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-June/015989.html" ref_id="CESA-2009:1102-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2541" ref_id="CVE-2004-2541"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0148" ref_id="CVE-2009-0148"/>
        <description>An updated cscope package that fixes multiple security issues is now
available for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
cscope is a mature, ncurses-based, C source-code tree browsing tool.
Multiple buffer overflow flaws were found in cscope. An attacker could
create a specially crafted source code file that could cause cscope to
crash or, possibly, execute arbitrary code when browsed with cscope.
(CVE-2004-2541, CVE-2009-0148)
All users of cscope are advised to upgrade to this updated package, which
contains backported patches to fix these issues. All running instances of
cscope must be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:21.461-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:31.370-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:24.944-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="cscope is earlier than 0:15.5-15.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:140831"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29253" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0012 -- netpbm security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>netpbm</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0012.html" ref_id="RHSA-2009:0012"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2721" ref_id="CVE-2007-2721"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3520" ref_id="CVE-2008-3520"/>
        <description>Updated netpbm packages that fix several security issues are now available
for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The netpbm package contains a library of functions for editing and
converting between various graphics file formats, including .pbm (portable
bitmaps), .pgm (portable graymaps), .pnm (portable anymaps), .ppm (portable
pixmaps), and others.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:00.157-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:31.184-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:24.663-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="netpbm-devel is earlier than 0:10.35-6.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:140332"/>
            <criterion comment="netpbm is earlier than 0:10.35-6.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:140004"/>
            <criterion comment="netpbm-progs is earlier than 0:10.35-6.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:140336"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="netpbm is earlier than 0:10.25-2.1.el4_7.4" test_ref="oval:org.mitre.oval:tst:140473"/>
            <criterion comment="netpbm-devel is earlier than 0:10.25-2.1.el4_7.4" test_ref="oval:org.mitre.oval:tst:140272"/>
            <criterion comment="netpbm-progs is earlier than 0:10.25-2.1.el4_7.4" test_ref="oval:org.mitre.oval:tst:140201"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29241" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0836 -- libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 2</platform>
          <platform>CentOS Linux 5</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0836.html" ref_id="RHSA-2008:0836"/>
        <reference source="CESA-2008:0836" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-August/015196.html" ref_id="CESA-2008:0836-CentOS 3"/>
        <reference source="CESA-2008:0836" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-August/015206.html" ref_id="CESA-2008:0836-CentOS 2"/>
        <reference source="CESA-2008:0836" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-August/015212.html" ref_id="CESA-2008:0836-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3281" ref_id="CVE-2008-3281"/>
        <description>Updated libxml2 packages that fix a security issue are now available.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The original fix used in this errata caused some applications using
the libxml2 library in an unexpected way to crash when used with updated
libxml2 packages. We have updated the packages for Red Hat Enterprise Linux
3, 4 and 5 to use a different fix that does not break affected
applications.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:31.572-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:30.129-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:23.676-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.4" test_ref="oval:org.mitre.oval:tst:139272"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.2.4" test_ref="oval:org.mitre.oval:tst:139288"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.2.4" test_ref="oval:org.mitre.oval:tst:138587"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.5.10-11" test_ref="oval:org.mitre.oval:tst:138962"/>
            <criterion comment="libxml2-devel is earlier than 0:2.5.10-11" test_ref="oval:org.mitre.oval:tst:139230"/>
            <criterion comment="libxml2-python is earlier than 0:2.5.10-11" test_ref="oval:org.mitre.oval:tst:138985"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.6.16-12.3" test_ref="oval:org.mitre.oval:tst:139290"/>
            <criterion comment="libxml2-devel is earlier than 0:2.6.16-12.3" test_ref="oval:org.mitre.oval:tst:139255"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.16-12.3" test_ref="oval:org.mitre.oval:tst:139002"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.2.3" test_ref="oval:org.mitre.oval:tst:139189"/>
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.3" test_ref="oval:org.mitre.oval:tst:139307"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.2.3" test_ref="oval:org.mitre.oval:tst:139280"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29237" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0978 -- firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>nss</product>
          <product>devhelp</product>
          <product>xulrunner</product>
          <product>yelp</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0978.html" ref_id="RHSA-2008:0978"/>
        <reference source="CESA-2008:0978" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-November/015406.html" ref_id="CESA-2008:0978-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0017" ref_id="CVE-2008-0017"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5014" ref_id="CVE-2008-5014"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5015" ref_id="CVE-2008-5015"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5016" ref_id="CVE-2008-5016"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5017" ref_id="CVE-2008-5017"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5018" ref_id="CVE-2008-5018"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5019" ref_id="CVE-2008-5019"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5021" ref_id="CVE-2008-5021"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5022" ref_id="CVE-2008-5022"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5023" ref_id="CVE-2008-5023"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5024" ref_id="CVE-2008-5024"/>
        <description>All firefox users should upgrade to these updated packages, which contain
backported patches that correct these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:09.636-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:29.333-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:23.162-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:140786"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:140705"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:140173"/>
            <criterion comment="devhelp is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:140658"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:140378"/>
            <criterion comment="yelp is earlier than 0:2.16.0-22.el5" test_ref="oval:org.mitre.oval:tst:140718"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:140533"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:140539"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:140415"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:140686"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:140618"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:3.0.4-1.el4" test_ref="oval:org.mitre.oval:tst:140180"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:140481"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:140626"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:3.0.4-1.el5.centos" test_ref="oval:org.mitre.oval:tst:140636"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el5.centos" test_ref="oval:org.mitre.oval:tst:140428"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el5.centos" test_ref="oval:org.mitre.oval:tst:140479"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5.centos" test_ref="oval:org.mitre.oval:tst:140399"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-3.el5.centos" test_ref="oval:org.mitre.oval:tst:140400"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29236" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0339 -- lcms security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>lcms</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0339.html" ref_id="RHSA-2009:0339"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0581" ref_id="CVE-2009-0581"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0723" ref_id="CVE-2009-0723"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0733" ref_id="CVE-2009-0733"/>
        <description>Updated lcms packages that resolve several security issues are now
available for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Little Color Management System (LittleCMS) is a
small-footprint, speed-optimized open source color management engine.
Multiple integer overflow flaws which could lead to heap-based buffer
overflows, as well as multiple insufficient input validation flaws, were
found in LittleCMS. An attacker could use these flaws to create a
specially-crafted image file which could cause an application using
LittleCMS to crash, or, possibly, execute arbitrary code when opened by a
victim. (CVE-2009-0723, CVE-2009-0733)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:54">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:39:59.191-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:29.055-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:22.865-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="lcms-devel is earlier than 0:1.18-0.1.beta1.el5_3.2" test_ref="oval:org.mitre.oval:tst:140468"/>
          <criterion comment="lcms is earlier than 0:1.18-0.1.beta1.el5_3.2" test_ref="oval:org.mitre.oval:tst:139897"/>
          <criterion comment="python-lcms is earlier than 0:1.18-0.1.beta1.el5_3.2" test_ref="oval:org.mitre.oval:tst:140047"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29234" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0575 -- rdesktop security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>rdesktop</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0575.html" ref_id="RHSA-2008:0575"/>
        <reference source="CESA-2008:0575" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-July/015161.html" ref_id="CESA-2008:0575-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1801" ref_id="CVE-2008-1801"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1803" ref_id="CVE-2008-1803"/>
        <description>An updated rdesktop package that fixes a security issue is now available for
Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
rdesktop is an open source client for Microsoft Windows NT Terminal Server
and Microsoft Windows 2000 and 2003 Terminal Services, capable of natively
using the Remote Desktop Protocol (RDP) to present the user's NT desktop.
No additional server extensions are required.
An integer underflow and integer signedness issue were discovered in the
rdesktop. If an attacker could convince a victim to connect to a malicious
RDP server, the attacker could cause the victim's rdesktop to crash or,
possibly, execute an arbitrary code. (CVE-2008-1801, CVE-2008-1803)
Users of rdesktop should upgrade to these updated packages, which contain a
backported patches to resolve these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:10.304-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:28.691-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:22.109-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="rdesktop is earlier than 0:1.4.1-6" test_ref="oval:org.mitre.oval:tst:139007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29232" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0580 -- vim security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>vim</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0580.html" ref_id="RHSA-2008:0580"/>
        <reference source="CESA-2008:0580" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-November/015453.html" ref_id="CESA-2008:0580-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2953" ref_id="CVE-2007-2953"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2712" ref_id="CVE-2008-2712"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3074" ref_id="CVE-2008-3074"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3075" ref_id="CVE-2008-3075"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4101" ref_id="CVE-2008-4101"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6235" ref_id="CVE-2008-6235"/>
        <description>Updated vim packages that fix security issues are now available for Red Hat
Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red Hat
Security Response Team.
Vim (Visual editor IMproved) is an updated and improved version of the vi
editor.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:39:54.719-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:27.978-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:21.148-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="vim-X11 is earlier than 2:7.0.109-4.el5_2.4z" test_ref="oval:org.mitre.oval:tst:140661"/>
          <criterion comment="vim-common is earlier than 2:7.0.109-4.el5_2.4z" test_ref="oval:org.mitre.oval:tst:140342"/>
          <criterion comment="vim-enhanced is earlier than 2:7.0.109-4.el5_2.4z" test_ref="oval:org.mitre.oval:tst:140675"/>
          <criterion comment="vim-minimal is earlier than 2:7.0.109-4.el5_2.4z" test_ref="oval:org.mitre.oval:tst:140608"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29230" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1530 -- firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>firefox</product>
          <product>nspr</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1530.html" ref_id="RHSA-2009:1530"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0689" ref_id="CVE-2009-0689"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1563" ref_id="CVE-2009-1563"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3274" ref_id="CVE-2009-3274"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3370" ref_id="CVE-2009-3370"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3372" ref_id="CVE-2009-3372"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3373" ref_id="CVE-2009-3373"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3374" ref_id="CVE-2009-3374"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3375" ref_id="CVE-2009-3375"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3376" ref_id="CVE-2009-3376"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3380" ref_id="CVE-2009-3380"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3382" ref_id="CVE-2009-3382"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3384" ref_id="CVE-2009-3384"/>
        <description>Updated firefox packages that fix several security issues are now available
for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox. nspr provides the Netscape
Portable Runtime (NSPR).
A flaw was found in the way Firefox handles form history. A malicious web
page could steal saved form data by synthesizing input events, causing the
browser to auto-fill form fields (which could then be read by an attacker).
(CVE-2009-3370)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:37">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:35.446-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:26.978-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:20.297-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:140125"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:140529"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:139804"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:140672"/>
            <criterion comment="nspr is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:140615"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:140801"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:3.0.15-3.el4" test_ref="oval:org.mitre.oval:tst:140313"/>
            <criterion comment="nspr is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:140404"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:140382"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29222" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1218 -- pidgin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 3</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1218.html" ref_id="RHSA-2009:1218"/>
        <reference source="CESA-2009:1218" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-August/016099.html" ref_id="CESA-2009:1218-CentOS 5"/>
        <reference source="CESA-2009:1218" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-August/016101.html" ref_id="CESA-2009:1218-CentOS 3"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2694" ref_id="CVE-2009-2694"/>
        <description>Updated pidgin packages that fix a security issue are now available for Red
Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.
Federico Muttis of Core Security Technologies discovered a flaw in Pidgin's
MSN protocol handler. If a user received a malicious MSN message, it was
possible to execute arbitrary code with the permissions of the user running
Pidgin. (CVE-2009-2694)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:54">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:24.315-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:26.577-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:19.396-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="finch-devel is earlier than 0:2.5.9-1.el5" test_ref="oval:org.mitre.oval:tst:139041"/>
            <criterion comment="libpurple-devel is earlier than 0:2.5.9-1.el5" test_ref="oval:org.mitre.oval:tst:139452"/>
            <criterion comment="pidgin-devel is earlier than 0:2.5.9-1.el5" test_ref="oval:org.mitre.oval:tst:139377"/>
            <criterion comment="finch is earlier than 0:2.5.9-1.el5" test_ref="oval:org.mitre.oval:tst:139031"/>
            <criterion comment="libpurple is earlier than 0:2.5.9-1.el5" test_ref="oval:org.mitre.oval:tst:138688"/>
            <criterion comment="libpurple-perl is earlier than 0:2.5.9-1.el5" test_ref="oval:org.mitre.oval:tst:139582"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.5.9-1.el5" test_ref="oval:org.mitre.oval:tst:139286"/>
            <criterion comment="pidgin is earlier than 0:2.5.9-1.el5" test_ref="oval:org.mitre.oval:tst:139348"/>
            <criterion comment="pidgin-perl is earlier than 0:2.5.9-1.el5" test_ref="oval:org.mitre.oval:tst:138841"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="pidgin is earlier than 0:1.5.1-4.el3" test_ref="oval:org.mitre.oval:tst:139437"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="finch is earlier than 0:2.5.9-1.el4" test_ref="oval:org.mitre.oval:tst:139287"/>
            <criterion comment="finch-devel is earlier than 0:2.5.9-1.el4" test_ref="oval:org.mitre.oval:tst:139679"/>
            <criterion comment="libpurple is earlier than 0:2.5.9-1.el4" test_ref="oval:org.mitre.oval:tst:139627"/>
            <criterion comment="libpurple-devel is earlier than 0:2.5.9-1.el4" test_ref="oval:org.mitre.oval:tst:139666"/>
            <criterion comment="libpurple-perl is earlier than 0:2.5.9-1.el4" test_ref="oval:org.mitre.oval:tst:138699"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.5.9-1.el4" test_ref="oval:org.mitre.oval:tst:139578"/>
            <criterion comment="pidgin is earlier than 0:2.5.9-1.el4" test_ref="oval:org.mitre.oval:tst:139603"/>
            <criterion comment="pidgin-devel is earlier than 0:2.5.9-1.el4" test_ref="oval:org.mitre.oval:tst:139572"/>
            <criterion comment="pidgin-perl is earlier than 0:2.5.9-1.el4" test_ref="oval:org.mitre.oval:tst:139493"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29217" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1219 -- libvorbis security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 3</platform>
          <product>libvorbis</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1219.html" ref_id="RHSA-2009:1219"/>
        <reference source="CESA-2009:1219" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-August/016093.html" ref_id="CESA-2009:1219-CentOS 5"/>
        <reference source="CESA-2009:1219" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-August/016103.html" ref_id="CESA-2009:1219-CentOS 3"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2663" ref_id="CVE-2009-2663"/>
        <description>Updated libvorbis packages that fix one security issue are now available
for Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The libvorbis packages contain runtime libraries for use in programs that
support Ogg Vorbis. Ogg Vorbis is a fully open, non-proprietary, patent-and
royalty-free, general-purpose compressed audio format.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:13.129-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:26.398-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:19.146-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libvorbis-devel is earlier than 1:1.1.2-3.el5_3.3" test_ref="oval:org.mitre.oval:tst:140822"/>
            <criterion comment="libvorbis is earlier than 1:1.1.2-3.el5_3.3" test_ref="oval:org.mitre.oval:tst:140685"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libvorbis is earlier than 1:1.0-11.el3" test_ref="oval:org.mitre.oval:tst:140798"/>
            <criterion comment="libvorbis-devel is earlier than 1:1.0-11.el3" test_ref="oval:org.mitre.oval:tst:140454"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libvorbis is earlier than 1:1.1.0-3.el4_8.2" test_ref="oval:org.mitre.oval:tst:140145"/>
            <criterion comment="libvorbis-devel is earlier than 1:1.1.0-3.el4_8.2" test_ref="oval:org.mitre.oval:tst:140898"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29215" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:1036 -- firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>nspr</product>
          <product>nss</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1036.html" ref_id="RHSA-2008:1036"/>
        <reference source="CESA-2008:1036" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-December/015503.html" ref_id="CESA-2008:1036-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5500" ref_id="CVE-2008-5500"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5501" ref_id="CVE-2008-5501"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5502" ref_id="CVE-2008-5502"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5505" ref_id="CVE-2008-5505"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5506" ref_id="CVE-2008-5506"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5507" ref_id="CVE-2008-5507"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5508" ref_id="CVE-2008-5508"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5510" ref_id="CVE-2008-5510"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5511" ref_id="CVE-2008-5511"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5512" ref_id="CVE-2008-5512"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5513" ref_id="CVE-2008-5513"/>
        <description>Note: after the errata packages are installed, Firefox must be restarted
for the update to take effect.
All firefox users should upgrade to these updated packages, which contain
backported patches that correct these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:39:56.307-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:26.152-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:18.703-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nspr-devel is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:140572"/>
            <criterion comment="nspr is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:140480"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:140463"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:140570"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:140563"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:140517"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:139656"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:140558"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:140355"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:140512"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:3.0.5-1.el4" test_ref="oval:org.mitre.oval:tst:140363"/>
            <criterion comment="nspr is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:140435"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:140211"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:140348"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:140624"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:3.0.5-1.el5.centos" test_ref="oval:org.mitre.oval:tst:140511"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-2.el5.centos" test_ref="oval:org.mitre.oval:tst:140600"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-2.el5.centos" test_ref="oval:org.mitre.oval:tst:140657"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-2.el5.centos" test_ref="oval:org.mitre.oval:tst:140577"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-2.el5.centos" test_ref="oval:org.mitre.oval:tst:140133"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:140574"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:140170"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:140417"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29213" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0057 -- squirrelmail security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>squirrelmail</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0057.html" ref_id="RHSA-2009:0057"/>
        <reference source="CESA-2009:0057" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-January/015560.html" ref_id="CESA-2009:0057-CentOS 3"/>
        <reference source="CESA-2009:0057" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-January/015564.html" ref_id="CESA-2009:0057-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0030" ref_id="CVE-2009-0030"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1580" ref_id="CVE-2009-1580"/>
        <description>An updated squirrelmail package that fixes a security issue is now
available for Red Hat Enterprise Linux 3, 4 and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
SquirrelMail is an easy-to-configure, standards-based, webmail package
written in PHP. It includes built-in PHP support for the IMAP and SMTP
protocols, and pure HTML 4.0 page-rendering (with no JavaScript required)
for maximum browser-compatibility, strong MIME support, address books, and
folder manipulation.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:05.150-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:25.963-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:18.411-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:140128"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-9.el3" test_ref="oval:org.mitre.oval:tst:140414"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el4_7.3" test_ref="oval:org.mitre.oval:tst:139950"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el5.centos.3" test_ref="oval:org.mitre.oval:tst:140438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29210" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:1023 -- pidgin security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1023.html" ref_id="RHSA-2008:1023"/>
        <reference source="CESA-2008:1023" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-December/015487.html" ref_id="CESA-2008:1023-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2955" ref_id="CVE-2008-2955"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2957" ref_id="CVE-2008-2957"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3532" ref_id="CVE-2008-3532"/>
        <description>Updated Pidgin packages that fix several security issues and bugs are now
available for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Pidgin is a multi-protocol Internet Messaging client.
A denial-of-service flaw was found in Pidgin's MSN protocol handler. If a
remote user was able to send, and the Pidgin user accepted, a
carefully-crafted file request, it could result in Pidgin crashing.
(CVE-2008-2955)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:34:37.735-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:25.660-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:18.019-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="finch-devel is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:139518"/>
            <criterion comment="libpurple-devel is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:139466"/>
            <criterion comment="pidgin-devel is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:139574"/>
            <criterion comment="finch is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:139502"/>
            <criterion comment="libpurple is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:139408"/>
            <criterion comment="libpurple-perl is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:139426"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:139662"/>
            <criterion comment="pidgin is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:139314"/>
            <criterion comment="pidgin-perl is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:139542"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="finch is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:138690"/>
            <criterion comment="finch-devel is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:139562"/>
            <criterion comment="libpurple is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:139653"/>
            <criterion comment="libpurple-devel is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:139678"/>
            <criterion comment="libpurple-perl is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:138716"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:139701"/>
            <criterion comment="pidgin is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:139597"/>
            <criterion comment="pidgin-devel is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:139429"/>
            <criterion comment="pidgin-perl is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:139513"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="pidgin-docs is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:139621"/>
            <criterion comment="enscript is earlier than 0:1.6.4-4.1.1.el5_2" test_ref="oval:org.mitre.oval:tst:139392"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29206" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1082 -- cups security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1082.html" ref_id="RHSA-2009:1082"/>
        <reference source="CESA-2009:1082" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-June/015963.html" ref_id="CESA-2009:1082-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0949" ref_id="CVE-2009-0949"/>
        <description>Updated cups packages that fix one security issue are now available for Red
Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The Common UNIX reg; Printing System (CUPS) provides a portable printing layer
for UNIX operating systems. The Internet Printing Protocol (IPP) allows
users to print and manage printing-related tasks over a network. 
A NULL pointer dereference flaw was found in the CUPS IPP routine, used for
processing incoming IPP requests for the CUPS scheduler. An attacker could
use this flaw to send specially-crafted IPP requests that would crash the
cupsd daemon. (CVE-2009-0949)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:18.606-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:25.300-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:17.465-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="cups-devel is earlier than 1:1.3.7-8.el5_3.6" test_ref="oval:org.mitre.oval:tst:140422"/>
          <criterion comment="cups is earlier than 1:1.3.7-8.el5_3.6" test_ref="oval:org.mitre.oval:tst:140915"/>
          <criterion comment="cups-libs is earlier than 1:1.3.7-8.el5_3.6" test_ref="oval:org.mitre.oval:tst:140962"/>
          <criterion comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.6" test_ref="oval:org.mitre.oval:tst:141005"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29205" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1201 -- java-1.6.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1201.html" ref_id="RHSA-2009:1201"/>
        <reference source="CESA-2009:1201" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-August/016064.html" ref_id="CESA-2009:1201-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0217" ref_id="CVE-2009-0217"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2475" ref_id="CVE-2009-2475"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2476" ref_id="CVE-2009-2476"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2625" ref_id="CVE-2009-2625"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2670" ref_id="CVE-2009-2670"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2671" ref_id="CVE-2009-2671"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2672" ref_id="CVE-2009-2672"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2673" ref_id="CVE-2009-2673"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2674" ref_id="CVE-2009-2674"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2675" ref_id="CVE-2009-2675"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2689" ref_id="CVE-2009-2689"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2690" ref_id="CVE-2009-2690"/>
        <description>Updated java-1.6.0-openjdk packages that fix several security issues and a
bug are now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit. The Java Runtime Environment (JRE)
contains the software and tools that users need to run applications written
using the Java programming language.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:12.105-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:24.614-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:16.774-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:140519"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:140015"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:140679"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:140794"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:140983"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29201" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0002 -- thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0002.html" ref_id="RHSA-2009:0002"/>
        <reference source="CESA-2009:0002" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-January/015524.html" ref_id="CESA-2009:0002-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5500" ref_id="CVE-2008-5500"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5501" ref_id="CVE-2008-5501"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5502" ref_id="CVE-2008-5502"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5503" ref_id="CVE-2008-5503"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5506" ref_id="CVE-2008-5506"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5507" ref_id="CVE-2008-5507"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5508" ref_id="CVE-2008-5508"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5511" ref_id="CVE-2008-5511"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5512" ref_id="CVE-2008-5512"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5513" ref_id="CVE-2008-5513"/>
        <description>Updated thunderbird packages that fix several security issues are now
available for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Mozilla Thunderbird is a standalone mail and newsgroup client.
Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2008-5500, CVE-2008-5501, CVE-2008-5502, CVE-2008-5511,
CVE-2008-5512, CVE-2008-5513)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:34:36.066-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:23.532-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:15.665-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="thunderbird is earlier than 0:1.5.0.12-18.el4" test_ref="oval:org.mitre.oval:tst:139301"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.19-1.el5_2" test_ref="oval:org.mitre.oval:tst:139593"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.19-1.el5.centos" test_ref="oval:org.mitre.oval:tst:139101"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29199" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0946 -- ed security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 2</platform>
          <platform>CentOS Linux 5</platform>
          <product>ed</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0946.html" ref_id="RHSA-2008:0946"/>
        <reference source="CESA-2008:0946" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-October/015334.html" ref_id="CESA-2008:0946-CentOS 3"/>
        <reference source="CESA-2008:0946" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-October/015337.html" ref_id="CESA-2008:0946-CentOS 2"/>
        <reference source="CESA-2008:0946" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-October/015339.html" ref_id="CESA-2008:0946-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3916" ref_id="CVE-2008-3916"/>
        <description>An updated ed package that fixes one security issue is now available for
Red Hat Enterprise Linux 2.1, 3, 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
ed is a line-oriented text editor, used to create, display, and modify
text files (both interactively and via shell scripts).
A heap-based buffer overflow was discovered in the way ed, the GNU line
editor, processed long file names. An attacker could create a file with a
specially-crafted name that could possibly execute an arbitrary code when
opened in the ed editor. (CVE-2008-3916)
Users of ed should upgrade to this updated package, which contains
a backported patch to resolve this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:19.710-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:23.127-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:15.121-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="ed is earlier than 0:0.2-33.30E.1" test_ref="oval:org.mitre.oval:tst:139066"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="ed is earlier than 0:0.2-36.el4_7.1" test_ref="oval:org.mitre.oval:tst:139005"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="ed is earlier than 0:0.2-39.el5_2" test_ref="oval:org.mitre.oval:tst:139003"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29197" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0971 -- net-snmp security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 3</platform>
          <product>net-snmp</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0971.html" ref_id="RHSA-2008:0971"/>
        <reference source="CESA-2008:0971" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-November/015365.html" ref_id="CESA-2008:0971-CentOS 5"/>
        <reference source="CESA-2008:0971" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-November/015367.html" ref_id="CESA-2008:0971-CentOS 3"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4309" ref_id="CVE-2008-4309"/>
        <description>Updated net-snmp packages that fix a security issue are now available for
Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The Simple Network Management Protocol (SNMP) is a protocol used for
network management.
A denial-of-service flaw was found in the way Net-SNMP processes SNMP
GETBULK requests. A remote attacker who issued a specially-crafted request
could cause the snmpd server to crash. (CVE-2008-4309)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:22.833-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:22.848-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:14.659-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="net-snmp-devel is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:140649"/>
            <criterion comment="net-snmp is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:140771"/>
            <criterion comment="net-snmp-libs is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:140589"/>
            <criterion comment="net-snmp-perl is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:140054"/>
            <criterion comment="net-snmp-utils is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:140641"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="net-snmp is earlier than 1:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:140637"/>
            <criterion comment="net-snmp-devel is earlier than 1:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:140286"/>
            <criterion comment="net-snmp-libs is earlier than 1:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:140294"/>
            <criterion comment="net-snmp-perl is earlier than 1:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:140746"/>
            <criterion comment="net-snmp-utils is earlier than 1:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:140780"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="net-snmp is earlier than 1:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:140733"/>
            <criterion comment="net-snmp-devel is earlier than 1:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:140354"/>
            <criterion comment="net-snmp-libs is earlier than 1:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:140768"/>
            <criterion comment="net-snmp-perl is earlier than 1:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:140764"/>
            <criterion comment="net-snmp-utils is earlier than 1:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:140557"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29196" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0333 -- libpng security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 2</platform>
          <product>libpng</product>
          <product>libpng10</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0333.html" ref_id="RHSA-2009:0333"/>
        <reference source="CESA-2009:0333" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-March/015674.html" ref_id="CESA-2009:0333-CentOS 2"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1382" ref_id="CVE-2008-1382"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0040" ref_id="CVE-2009-0040"/>
        <description>Updated libpng and libpng10 packages that fix a couple of security issues
are now available for Red Hat Enterprise Linux 2.1, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The libpng packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.
A flaw was discovered in libpng that could result in libpng trying to
freerandom memory if certain, unlikely error conditions occurred. If a
carefully-crafted PNG file was loaded by an application linked against
libpng, it could cause the application to crash or, potentially, execute
arbitrary code with the privileges of the user running the application.
(CVE-2009-0040)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:28.556-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:22.571-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:14.356-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libpng-devel is earlier than 2:1.2.10-7.1.el5_3.2" test_ref="oval:org.mitre.oval:tst:140055"/>
            <criterion comment="libpng is earlier than 2:1.2.10-7.1.el5_3.2" test_ref="oval:org.mitre.oval:tst:140045"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libpng is earlier than 2:1.2.7-3.el4_7.2" test_ref="oval:org.mitre.oval:tst:140228"/>
            <criterion comment="libpng-devel is earlier than 2:1.2.7-3.el4_7.2" test_ref="oval:org.mitre.oval:tst:140264"/>
            <criterion comment="libpng10 is earlier than 2:1.0.16-3.el4_7.3" test_ref="oval:org.mitre.oval:tst:140306"/>
            <criterion comment="libpng10-devel is earlier than 2:1.0.16-3.el4_7.3" test_ref="oval:org.mitre.oval:tst:140434"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29195" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0296 -- icu security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>icu</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0296.html" ref_id="RHSA-2009:0296"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1036" ref_id="CVE-2008-1036"/>
        <description>Updated icu packages that fix a security issue are now available for Red
Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The International Components for Unicode (ICU) library provides robust and
full-featured Unicode services.
A flaw was found in the way ICU processed certain, invalid, encoded data.
If an application used ICU to decode malformed, multibyte, character data,
it may have been possible to bypass certain content protection mechanisms,
or display information in a manner misleading to the user. (CVE-2008-1036)
All users of icu should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:30.502-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:22.396-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:14.179-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libicu-devel is earlier than 0:3.6-5.11.2" test_ref="oval:org.mitre.oval:tst:140237"/>
          <criterion comment="icu is earlier than 0:3.6-5.11.2" test_ref="oval:org.mitre.oval:tst:140448"/>
          <criterion comment="libicu is earlier than 0:3.6-5.11.2" test_ref="oval:org.mitre.oval:tst:140335"/>
          <criterion comment="libicu-doc is earlier than 0:3.6-5.11.2" test_ref="oval:org.mitre.oval:tst:140374"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29193" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0431 -- kdegraphics security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>kdegraphics</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0431.html" ref_id="RHSA-2009:0431"/>
        <reference source="CESA-2009:0431" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-May/015868.html" ref_id="CESA-2009:0431-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0146" ref_id="CVE-2009-0146"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0147" ref_id="CVE-2009-0147"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0166" ref_id="CVE-2009-0166"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0195" ref_id="CVE-2009-0195"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0799" ref_id="CVE-2009-0799"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0800" ref_id="CVE-2009-0800"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1179" ref_id="CVE-2009-1179"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1180" ref_id="CVE-2009-1180"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1181" ref_id="CVE-2009-1181"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1182" ref_id="CVE-2009-1182"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1183" ref_id="CVE-2009-1183"/>
        <description>Updated kdegraphics packages that fix multiple security issues are now
available for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The kdegraphics packages contain applications for the K Desktop
Environment, including KPDF, a viewer for Portable Document Format (PDF)
files.
Multiple integer overflow flaws were found in KPDF's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause KPDF to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0147,
CVE-2009-1179)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:34:28.029-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:21.350-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:13.779-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:139459"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:139206"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kdegraphics is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:139444"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:139227"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29192" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0855 -- openssh security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openssh</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0855.html" ref_id="RHSA-2008:0855"/>
        <reference source="CESA-2008:0855" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-August/015194.html" ref_id="CESA-2008:0855-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4752" ref_id="CVE-2007-4752"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3844" ref_id="CVE-2008-3844"/>
        <description>Updated openssh packages are now available for Red Hat Enterprise Linux 4,
Red Hat Enterprise Linux 5, and Red Hat Enterprise Linux 4.5 Extended
Update Support.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:13.970-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:21.138-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:13.185-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssh is earlier than 0:3.9p1-11.el4_7" test_ref="oval:org.mitre.oval:tst:139057"/>
            <criterion comment="openssh-askpass is earlier than 0:3.9p1-11.el4_7" test_ref="oval:org.mitre.oval:tst:138943"/>
            <criterion comment="openssh-askpass-gnome is earlier than 0:3.9p1-11.el4_7" test_ref="oval:org.mitre.oval:tst:139241"/>
            <criterion comment="openssh-clients is earlier than 0:3.9p1-11.el4_7" test_ref="oval:org.mitre.oval:tst:138914"/>
            <criterion comment="openssh-server is earlier than 0:3.9p1-11.el4_7" test_ref="oval:org.mitre.oval:tst:139218"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssh is earlier than 0:4.3p2-26.el5_2.1" test_ref="oval:org.mitre.oval:tst:139199"/>
            <criterion comment="openssh-askpass is earlier than 0:4.3p2-26.el5_2.1" test_ref="oval:org.mitre.oval:tst:139215"/>
            <criterion comment="openssh-clients is earlier than 0:4.3p2-26.el5_2.1" test_ref="oval:org.mitre.oval:tst:139246"/>
            <criterion comment="openssh-server is earlier than 0:4.3p2-26.el5_2.1" test_ref="oval:org.mitre.oval:tst:138970"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29190" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1490 -- squirrelmail security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <product>squirrelmail</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1490.html" ref_id="RHSA-2009:1490"/>
        <reference source="CESA-2009:1490" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-October/016181.html" ref_id="CESA-2009:1490-CentOS 3"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2964" ref_id="CVE-2009-2964"/>
        <description>An updated squirrelmail package that fixes several security issues is now
available for Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:05.627-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:21.012-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:12.995-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el5_4.10" test_ref="oval:org.mitre.oval:tst:140697"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-16.el3" test_ref="oval:org.mitre.oval:tst:140248"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el4_8.8" test_ref="oval:org.mitre.oval:tst:140565"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29188" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1162 -- firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1162.html" ref_id="RHSA-2009:1162"/>
        <reference source="CESA-2009:1162" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-July/016046.html" ref_id="CESA-2009:1162-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2462" ref_id="CVE-2009-2462"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2463" ref_id="CVE-2009-2463"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2464" ref_id="CVE-2009-2464"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2465" ref_id="CVE-2009-2465"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2466" ref_id="CVE-2009-2466"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2467" ref_id="CVE-2009-2467"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2469" ref_id="CVE-2009-2469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2470" ref_id="CVE-2009-2470"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2471" ref_id="CVE-2009-2471"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2472" ref_id="CVE-2009-2472"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2664" ref_id="CVE-2009-2664"/>
        <description>Updated firefox packages that fix several security issues are now available
for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:03.429-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:20.039-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:11.965-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:140947"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:140836"/>
            <criterion comment="firefox is earlier than 0:3.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:140903"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:140477"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="firefox is earlier than 0:3.0.12-1.el4" test_ref="oval:org.mitre.oval:tst:140978"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:3.0.12-1.el5.centos" test_ref="oval:org.mitre.oval:tst:140017"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.12-1.el5" test_ref="oval:org.mitre.oval:tst:140628"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.12-1.el5" test_ref="oval:org.mitre.oval:tst:140971"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.12-1.el5" test_ref="oval:org.mitre.oval:tst:140439"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29185" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0937 -- cups security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0937.html" ref_id="RHSA-2008:0937"/>
        <reference source="CESA-2008:0937" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-October/015312.html" ref_id="CESA-2008:0937-CentOS 3"/>
        <reference source="CESA-2008:0937" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-October/015324.html" ref_id="CESA-2008:0937-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3639" ref_id="CVE-2008-3639"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3640" ref_id="CVE-2008-3640"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3641" ref_id="CVE-2008-3641"/>
        <description>Updated cups packages that fix multiple security issues are now available
for Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:41.679-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:19.782-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:11.594-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cups-devel is earlier than 1:1.2.4-11.18.el5_2.2" test_ref="oval:org.mitre.oval:tst:139113"/>
            <criterion comment="cups is earlier than 1:1.2.4-11.18.el5_2.2" test_ref="oval:org.mitre.oval:tst:138134"/>
            <criterion comment="cups-libs is earlier than 1:1.2.4-11.18.el5_2.2" test_ref="oval:org.mitre.oval:tst:138560"/>
            <criterion comment="cups-lpd is earlier than 1:1.2.4-11.18.el5_2.2" test_ref="oval:org.mitre.oval:tst:139114"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cups is earlier than 1:1.1.17-13.3.54" test_ref="oval:org.mitre.oval:tst:138755"/>
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.54" test_ref="oval:org.mitre.oval:tst:139023"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.54" test_ref="oval:org.mitre.oval:tst:138986"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.1" test_ref="oval:org.mitre.oval:tst:139059"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.1" test_ref="oval:org.mitre.oval:tst:138971"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.1" test_ref="oval:org.mitre.oval:tst:138730"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29183" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1126 -- thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1126.html" ref_id="RHSA-2009:1126"/>
        <reference source="CESA-2009:1126" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-June/016011.html" ref_id="CESA-2009:1126-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1303" ref_id="CVE-2009-1303"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1305" ref_id="CVE-2009-1305"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1306" ref_id="CVE-2009-1306"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1307" ref_id="CVE-2009-1307"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1308" ref_id="CVE-2009-1308"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1309" ref_id="CVE-2009-1309"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1392" ref_id="CVE-2009-1392"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1833" ref_id="CVE-2009-1833"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1836" ref_id="CVE-2009-1836"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1838" ref_id="CVE-2009-1838"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2210" ref_id="CVE-2009-2210"/>
        <description>An updated thunderbird package that fixes several security issues is now
available for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Mozilla Thunderbird is a standalone mail and newsgroup client.
Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2009-1392, CVE-2009-1303, CVE-2009-1305, CVE-2009-1833,
CVE-2009-1838)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:54">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:32.017-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:18.983-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:10.888-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.22-2.el5_3" test_ref="oval:org.mitre.oval:tst:139169"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.22-2.el5.centos" test_ref="oval:org.mitre.oval:tst:139051"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29179" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1164 -- tomcat security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>tomcat5</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1164.html" ref_id="RHSA-2009:1164"/>
        <reference source="CESA-2009:1164" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-July/016048.html" ref_id="CESA-2009:1164-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5333" ref_id="CVE-2007-5333"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5515" ref_id="CVE-2008-5515"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0033" ref_id="CVE-2009-0033"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0580" ref_id="CVE-2009-0580"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0781" ref_id="CVE-2009-0781"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0783" ref_id="CVE-2009-0783"/>
        <description>Updated tomcat packages that fix several security issues are now available
for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:11.254-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:17.944-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:09.951-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:140659"/>
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:140931"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:140568"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:140916"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:140852"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:140467"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:140875"/>
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:140447"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:140908"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:140872"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:140578"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29178" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0397 -- firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0397.html" ref_id="RHSA-2009:0397"/>
        <reference source="CESA-2009:0397" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-April/015756.html" ref_id="CESA-2009:0397-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1044" ref_id="CVE-2009-1044"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1169" ref_id="CVE-2009-1169"/>
        <description>Updated firefox packages that fix two security issues are now available for
Red Hat Enterprise Linux 4 and 5.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.
A memory corruption flaw was discovered in the way Firefox handles XML
files containing an XSLT transform. A remote attacker could use this flaw
to crash Firefox or, potentially, execute arbitrary code as the user
running Firefox. (CVE-2009-1169)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:01.904-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:17.725-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:09.695-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.7-3.el5" test_ref="oval:org.mitre.oval:tst:140377"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-3.el5" test_ref="oval:org.mitre.oval:tst:140429"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.7-3.el5" test_ref="oval:org.mitre.oval:tst:140375"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="firefox is earlier than 0:3.0.7-3.el4" test_ref="oval:org.mitre.oval:tst:140261"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29171" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0345 -- ghostscript security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <product>ghostscript</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0345.html" ref_id="RHSA-2009:0345"/>
        <reference source="CESA-2009:0345" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-March/015688.html" ref_id="CESA-2009:0345-CentOS 3"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0583" ref_id="CVE-2009-0583"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0584" ref_id="CVE-2009-0584"/>
        <description>Updated ghostscript packages that fix multiple security issues are now
available for Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Ghostscript is a set of software that provides a PostScript(TM)
interpreter, a set of C procedures (the Ghostscript library, which
implements the graphics capabilities in the PostScript language) and
an interpreter for Portable Document Format (PDF) files. 
Multiple integer overflow flaws which could lead to heap-based buffer
overflows, as well as multiple insufficient input validation flaws, were
found in Ghostscript's International Color Consortium Format library
(icclib). Using specially-crafted ICC profiles, an attacker could create a
malicious PostScript or PDF file with embedded images which could cause
Ghostscript to crash, or, potentially, execute arbitrary code when opened
by the victim. (CVE-2009-0583, CVE-2009-0584)
All users of ghostscript are advised to upgrade to these updated packages,
which contain a backported patch to correct these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:12.846-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:17.255-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:09.128-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ghostscript-devel is earlier than 0:8.15.2-9.4.el5_3.4" test_ref="oval:org.mitre.oval:tst:140320"/>
            <criterion comment="ghostscript is earlier than 0:8.15.2-9.4.el5_3.4" test_ref="oval:org.mitre.oval:tst:140458"/>
            <criterion comment="ghostscript-gtk is earlier than 0:8.15.2-9.4.el5_3.4" test_ref="oval:org.mitre.oval:tst:139652"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ghostscript is earlier than 0:7.05-32.1.17" test_ref="oval:org.mitre.oval:tst:140393"/>
            <criterion comment="ghostscript-devel is earlier than 0:7.05-32.1.17" test_ref="oval:org.mitre.oval:tst:140107"/>
            <criterion comment="hpijs is earlier than 0:1.3-32.1.17" test_ref="oval:org.mitre.oval:tst:140281"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ghostscript is earlier than 0:7.07-33.2.el4_7.5" test_ref="oval:org.mitre.oval:tst:139961"/>
            <criterion comment="ghostscript-devel is earlier than 0:7.07-33.2.el4_7.5" test_ref="oval:org.mitre.oval:tst:140381"/>
            <criterion comment="ghostscript-gtk is earlier than 0:7.07-33.2.el4_7.5" test_ref="oval:org.mitre.oval:tst:140285"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29170" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1561 -- libvorbis security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>libvorbis</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1561.html" ref_id="RHSA-2009:1561"/>
        <reference source="CESA-2009:1561" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-November/016308.html" ref_id="CESA-2009:1561-CentOS 3"/>
        <reference source="CESA-2009:1561" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-November/016323.html" ref_id="CESA-2009:1561-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3379" ref_id="CVE-2009-3379"/>
        <description>Updated libvorbis packages that fix multiple security issues are now
available for Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The libvorbis packages contain runtime libraries for use in programs that
support Ogg Vorbis. Ogg Vorbis is a fully open, non-proprietary, patent-and
royalty-free, general-purpose compressed audio format.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:35">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:37:49.325-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:17.067-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:08.846-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libvorbis-devel is earlier than 1:1.1.2-3.el5_4.4" test_ref="oval:org.mitre.oval:tst:139939"/>
            <criterion comment="libvorbis is earlier than 1:1.1.2-3.el5_4.4" test_ref="oval:org.mitre.oval:tst:139936"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libvorbis is earlier than 1:1.0-12.el3" test_ref="oval:org.mitre.oval:tst:140266"/>
            <criterion comment="libvorbis-devel is earlier than 1:1.0-12.el3" test_ref="oval:org.mitre.oval:tst:140206"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libvorbis is earlier than 1:1.1.0-3.el4_8.3" test_ref="oval:org.mitre.oval:tst:140124"/>
            <criterion comment="libvorbis-devel is earlier than 1:1.1.0-3.el4_8.3" test_ref="oval:org.mitre.oval:tst:140011"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29169" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1186 -- nspr and nss security, bug fix, and enhancement update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>nspr</product>
          <product>nss</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1186.html" ref_id="RHSA-2009:1186"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2404" ref_id="CVE-2009-2404"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2408" ref_id="CVE-2009-2408"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2409" ref_id="CVE-2009-2409"/>
        <description>Updated nspr and nss packages that fix security issues, bugs, and add an
enhancement are now available for Red Hat Enterprise Linux 5.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:34.155-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:16.710-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:08.437-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="nspr-devel is earlier than 0:4.7.4-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:140616"/>
          <criterion comment="nss-devel is earlier than 0:3.12.3.99.3-1.el5_3.2" test_ref="oval:org.mitre.oval:tst:140990"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.3.99.3-1.el5_3.2" test_ref="oval:org.mitre.oval:tst:140727"/>
          <criterion comment="nspr is earlier than 0:4.7.4-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:140868"/>
          <criterion comment="nss is earlier than 0:3.12.3.99.3-1.el5_3.2" test_ref="oval:org.mitre.oval:tst:140172"/>
          <criterion comment="nss-tools is earlier than 0:3.12.3.99.3-1.el5_3.2" test_ref="oval:org.mitre.oval:tst:140787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29167" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0789 -- dnsmasq security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>dnsmasq</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0789.html" ref_id="RHSA-2008:0789"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447" ref_id="CVE-2008-1447"/>
        <description>An updated dnsmasq package that implements UDP source-port randomization
is now available for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Dnsmasq is lightweight DNS forwarder and DHCP server. It is designed to
provide DNS and, optionally, DHCP, to a small network.
The dnsmasq DNS resolver used a fixed source UDP port. This could have made
DNS spoofing attacks easier. dnsmasq has been updated to use random UDP
source ports, helping to make DNS spoofing attacks harder. (CVE-2008-1447)
All dnsmasq users are advised to upgrade to this updated package, that
upgrades dnsmasq to version 2.45, which resolves this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:28.873-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:16.564-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:08.314-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="dnsmasq is earlier than 0:2.45-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:139204"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29166" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0258 -- thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0258.html" ref_id="RHSA-2009:0258"/>
        <reference source="CESA-2009:0258" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-May/015869.html" ref_id="CESA-2009:0258-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0352" ref_id="CVE-2009-0352"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0353" ref_id="CVE-2009-0353"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0355" ref_id="CVE-2009-0355"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0772" ref_id="CVE-2009-0772"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0774" ref_id="CVE-2009-0774"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0775" ref_id="CVE-2009-0775"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0776" ref_id="CVE-2009-0776"/>
        <description>An updated thunderbird package that fixes several security issues is now
available for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Mozilla Thunderbird is a standalone mail and newsgroup client.
Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2009-0352, CVE-2009-0353, CVE-2009-0772, CVE-2009-0774,
CVE-2009-0775)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:34:31.298-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:15.913-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:07.962-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="thunderbird is earlier than 0:1.5.0.12-19.el4" test_ref="oval:org.mitre.oval:tst:139441"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.21-1.el5" test_ref="oval:org.mitre.oval:tst:138696"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.21-1.el5.centos" test_ref="oval:org.mitre.oval:tst:139524"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29163" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1203 -- subversion security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1203.html" ref_id="RHSA-2009:1203"/>
        <reference source="CESA-2009:1203" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-August/016070.html" ref_id="CESA-2009:1203-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2411" ref_id="CVE-2009-2411"/>
        <description>Updated subversion packages that fix multiple security issues are now
available for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:39.463-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:15.325-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:07.212-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="mod_dav_svn is earlier than 0:1.4.2-4.el5_3.1" test_ref="oval:org.mitre.oval:tst:140893"/>
            <criterion comment="subversion is earlier than 0:1.4.2-4.el5_3.1" test_ref="oval:org.mitre.oval:tst:139972"/>
            <criterion comment="subversion-devel is earlier than 0:1.4.2-4.el5_3.1" test_ref="oval:org.mitre.oval:tst:140738"/>
            <criterion comment="subversion-javahl is earlier than 0:1.4.2-4.el5_3.1" test_ref="oval:org.mitre.oval:tst:140890"/>
            <criterion comment="subversion-perl is earlier than 0:1.4.2-4.el5_3.1" test_ref="oval:org.mitre.oval:tst:140958"/>
            <criterion comment="subversion-ruby is earlier than 0:1.4.2-4.el5_3.1" test_ref="oval:org.mitre.oval:tst:140826"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="mod_dav_svn is earlier than 0:1.1.4-3.el4_8.2" test_ref="oval:org.mitre.oval:tst:140899"/>
            <criterion comment="subversion is earlier than 0:1.1.4-3.el4_8.2" test_ref="oval:org.mitre.oval:tst:140452"/>
            <criterion comment="subversion-devel is earlier than 0:1.1.4-3.el4_8.2" test_ref="oval:org.mitre.oval:tst:140532"/>
            <criterion comment="subversion-perl is earlier than 0:1.1.4-3.el4_8.2" test_ref="oval:org.mitre.oval:tst:140509"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29162" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0835 -- openoffice.org security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openoffice.org</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0835.html" ref_id="RHSA-2008:0835"/>
        <reference source="CESA-2008:0835" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-August/015230.html" ref_id="CESA-2008:0835-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3282" ref_id="CVE-2008-3282"/>
        <description>Updated openoffice.org packages that fix a security issue are now available
for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet, presentation manager,
formula editor, and a drawing program.
A numeric truncation error was found in the OpenOffice.org memory
allocator. If a carefully crafted file was opened by a victim, an attacker
could use this flaw to crash OpenOffice.org or, possibly, execute arbitrary
code. (CVE-2008-3282)
All users of openoffice.org are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:34:35.063-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:14.870-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:06.304-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openoffice.org-sdk is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139898"/>
          <criterion comment="openoffice.org-sdk-doc is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139815"/>
          <criterion comment="openoffice.org-base is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139647"/>
          <criterion comment="openoffice.org-calc is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139903"/>
          <criterion comment="openoffice.org-core is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139674"/>
          <criterion comment="openoffice.org-draw is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139812"/>
          <criterion comment="openoffice.org-emailmerge is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139565"/>
          <criterion comment="openoffice.org-graphicfilter is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139844"/>
          <criterion comment="openoffice.org-headless is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139613"/>
          <criterion comment="openoffice.org-impress is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139796"/>
          <criterion comment="openoffice.org-javafilter is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139704"/>
          <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139743"/>
          <criterion comment="openoffice.org-langpack-ar is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139765"/>
          <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139868"/>
          <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139742"/>
          <criterion comment="openoffice.org-langpack-bn is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139895"/>
          <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139347"/>
          <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139394"/>
          <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139362"/>
          <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139144"/>
          <criterion comment="openoffice.org-langpack-de is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139165"/>
          <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:138994"/>
          <criterion comment="openoffice.org-langpack-es is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139739"/>
          <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139692"/>
          <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139700"/>
          <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139828"/>
          <criterion comment="openoffice.org-langpack-fr is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139738"/>
          <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139978"/>
          <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139511"/>
          <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139770"/>
          <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139629"/>
          <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139970"/>
          <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139904"/>
          <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139512"/>
          <criterion comment="openoffice.org-langpack-it is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139551"/>
          <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139920"/>
          <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139824"/>
          <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139331"/>
          <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139345"/>
          <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139989"/>
          <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139888"/>
          <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139890"/>
          <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139541"/>
          <criterion comment="openoffice.org-langpack-nl is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139873"/>
          <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139543"/>
          <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139636"/>
          <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139081"/>
          <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139710"/>
          <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139343"/>
          <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139947"/>
          <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139861"/>
          <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139302"/>
          <criterion comment="openoffice.org-langpack-ru is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139926"/>
          <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139879"/>
          <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139975"/>
          <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139549"/>
          <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139910"/>
          <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139375"/>
          <criterion comment="openoffice.org-langpack-sv is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139623"/>
          <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139716"/>
          <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139579"/>
          <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139945"/>
          <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139990"/>
          <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139891"/>
          <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139928"/>
          <criterion comment="openoffice.org-langpack-ur is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139830"/>
          <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139462"/>
          <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139806"/>
          <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139940"/>
          <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139558"/>
          <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139482"/>
          <criterion comment="openoffice.org-math is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139880"/>
          <criterion comment="openoffice.org-pyuno is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139693"/>
          <criterion comment="openoffice.org-testtools is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139714"/>
          <criterion comment="openoffice.org-writer is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139037"/>
          <criterion comment="openoffice.org-xsltfilter is earlier than 1:2.3.0-6.5.2.el5_2" test_ref="oval:org.mitre.oval:tst:139899"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29154" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1193 -- kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1193.html" ref_id="RHSA-2009:1193"/>
        <reference source="CESA-2009:1193" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-August/016062.html" ref_id="CESA-2009:1193-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5966" ref_id="CVE-2007-5966"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1385" ref_id="CVE-2009-1385"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1388" ref_id="CVE-2009-1388"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1389" ref_id="CVE-2009-1389"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1895" ref_id="CVE-2009-1895"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2406" ref_id="CVE-2009-2406"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2407" ref_id="CVE-2009-2407"/>
        <description>Updated kernel packages that fix several security issues and several bugs
are now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The kernel packages contain the Linux kernel, the core of any Linux
operating system.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:16:59.781-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:14.202-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:05.408-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:140973"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:140912"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:140666"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:140432"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:140981"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:140579"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:140937"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:140939"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:141008"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:140858"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29153" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1243 -- Red Hat Enterprise Linux 5.4 kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1243.html" ref_id="RHSA-2009:1243"/>
        <reference source="CESA-2009:1243" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-September/016137.html" ref_id="CESA-2009:1243-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0745" ref_id="CVE-2009-0745"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0746" ref_id="CVE-2009-0746"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0747" ref_id="CVE-2009-0747"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0748" ref_id="CVE-2009-0748"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2847" ref_id="CVE-2009-2847"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2848" ref_id="CVE-2009-2848"/>
        <description>Updated kernel packages that fix security issues, address several hundred
bugs and add numerous enhancements are now available as part of the ongoing
support and maintenance of Red Hat Enterprise Linux version 5. This is the
fourth regular update.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The kernel packages contain the Linux kernel, the core of any Linux
operating system.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:06.828-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:13.794-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:04.651-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:140284"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:140730"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:140620"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:140619"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:140315"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:140502"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:140871"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:140581"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:140552"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:140791"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29150" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0544 -- php security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0544.html" ref_id="RHSA-2008:0544"/>
        <reference source="CESA-2008:0544" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-July/015126.html" ref_id="CESA-2008:0544-CentOS 3"/>
        <reference source="CESA-2008:0544" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-July/015142.html" ref_id="CESA-2008:0544-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4782" ref_id="CVE-2007-4782"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5898" ref_id="CVE-2007-5898"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5899" ref_id="CVE-2007-5899"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2051" ref_id="CVE-2008-2051"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2107" ref_id="CVE-2008-2107"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2108" ref_id="CVE-2008-2108"/>
        <description>Updated PHP packages that fix several security issues are now available for
Red Hat Enterprise Linux 3 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.
It was discovered that the PHP escapeshellcmdfunction did not properly
escape multi-byte characters which are not valid in the locale used by the
script. This could allow an attacker to bypass quoting restrictions imposed
by escapeshellcmdand execute arbitrary commands if the PHP script was
using certain locales. Scripts using the default UTF-8 locale are not
affected by this issue. (CVE-2008-2051)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:47.883-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:13.188-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:03.202-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:139056"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:139044"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:138671"/>
            <criterion comment="php-common is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:139149"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:139124"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:139329"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:139276"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:138598"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:139194"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:139139"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:139266"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:139275"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:139128"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:139024"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:139019"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:138416"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:139231"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:138915"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:138786"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:4.3.2-48.ent" test_ref="oval:org.mitre.oval:tst:138818"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-48.ent" test_ref="oval:org.mitre.oval:tst:139193"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-48.ent" test_ref="oval:org.mitre.oval:tst:139184"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-48.ent" test_ref="oval:org.mitre.oval:tst:139257"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-48.ent" test_ref="oval:org.mitre.oval:tst:138603"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-48.ent" test_ref="oval:org.mitre.oval:tst:139159"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-48.ent" test_ref="oval:org.mitre.oval:tst:139179"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29144" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0584 -- pidgin security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0584.html" ref_id="RHSA-2008:0584"/>
        <reference source="CESA-2008:0584" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-July/015085.html" ref_id="CESA-2008:0584-CentOS 3"/>
        <reference source="CESA-2008:0584" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-July/015098.html" ref_id="CESA-2008:0584-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2927" ref_id="CVE-2008-2927"/>
        <description>Updated Pidgin packages that fix a security issue and address a bug are now
available for Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
Pidgin is a multi-protocol Internet Messaging client.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:55:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:34:32.207-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:12.109-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:01.372-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="finch-devel is earlier than 0:2.3.1-2.el5_2" test_ref="oval:org.mitre.oval:tst:139856"/>
            <criterion comment="libpurple-devel is earlier than 0:2.3.1-2.el5_2" test_ref="oval:org.mitre.oval:tst:140003"/>
            <criterion comment="pidgin-devel is earlier than 0:2.3.1-2.el5_2" test_ref="oval:org.mitre.oval:tst:139797"/>
            <criterion comment="finch is earlier than 0:2.3.1-2.el5_2" test_ref="oval:org.mitre.oval:tst:139818"/>
            <criterion comment="libpurple is earlier than 0:2.3.1-2.el5_2" test_ref="oval:org.mitre.oval:tst:139728"/>
            <criterion comment="libpurple-perl is earlier than 0:2.3.1-2.el5_2" test_ref="oval:org.mitre.oval:tst:139849"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.3.1-2.el5_2" test_ref="oval:org.mitre.oval:tst:139951"/>
            <criterion comment="pidgin is earlier than 0:2.3.1-2.el5_2" test_ref="oval:org.mitre.oval:tst:139977"/>
            <criterion comment="pidgin-perl is earlier than 0:2.3.1-2.el5_2" test_ref="oval:org.mitre.oval:tst:139869"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="pidgin is earlier than 0:1.5.1-2.el3" test_ref="oval:org.mitre.oval:tst:139919"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="pidgin is earlier than 0:1.5.1-2.el4" test_ref="oval:org.mitre.oval:tst:140033"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29143" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0018 -- xterm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>xterm</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0018.html" ref_id="RHSA-2009:0018"/>
        <reference source="CESA-2009:0018" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-January/015520.html" ref_id="CESA-2009:0018-CentOS 3"/>
        <reference source="CESA-2009:0018" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-January/015526.html" ref_id="CESA-2009:0018-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2383" ref_id="CVE-2008-2383"/>
        <description>An updated xterm package to correct a security issue is now available for
Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The xterm program is a terminal emulator for the X Window System.
A flaw was found in the xterm handling of Device Control Request Status
String (DECRQSS) escape sequences. An attacker could create a malicious
text file (or log entry, if unfiltered) that could run arbitrary commands
if read by a victim inside an xterm window. (CVE-2008-2383)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:20.130-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:11.884-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:01.116-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="xterm is earlier than 0:179-11.EL3" test_ref="oval:org.mitre.oval:tst:140550"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="xterm is earlier than 0:192-8.el4_7.2" test_ref="oval:org.mitre.oval:tst:140418"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="xterm is earlier than 0:215-5.el5_2.2" test_ref="oval:org.mitre.oval:tst:140441"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29140" version="3" class="patch">
      <metadata>
        <title>RHSA-2015:0808 -- java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2015-0808.html" ref_id="RHSA-2015:0808"/>
        <reference source="CESA-2015:0808" ref_url="http://lists.centos.org/pipermail/centos-announce/2015-April/021065.html" ref_id="CESA-2015:0808-CentOS 7"/>
        <reference source="CESA-2015:0808" ref_url="http://lists.centos.org/pipermail/centos-announce/2015-April/021068.html" ref_id="CESA-2015:0808-CentOS 6"/>
        <reference source="CESA-2015:0808" ref_url="http://lists.centos.org/pipermail/centos-announce/2015-April/021073.html" ref_id="CESA-2015:0808-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1080" ref_id="CVE-2005-1080"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0460" ref_id="CVE-2015-0460"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0469" ref_id="CVE-2015-0469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0477" ref_id="CVE-2015-0477"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0478" ref_id="CVE-2015-0478"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0480" ref_id="CVE-2015-0480"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0488" ref_id="CVE-2015-0488"/>
        <description>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.
An off-by-one flaw, leading to a buffer overflow, was found in the font
parsing code in the 2D component in OpenJDK. A specially crafted font file
could possibly cause the Java Virtual Machine to execute arbitrary code,
allowing an untrusted Java application or applet to bypass Java sandbox
restrictions. (CVE-2015-0469)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:37:41.628-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:11.407-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:00.788-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.35-1.13.7.1.el5_11" test_ref="oval:org.mitre.oval:tst:139368"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.35-1.13.7.1.el5_11" test_ref="oval:org.mitre.oval:tst:139581"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.35-1.13.7.1.el5_11" test_ref="oval:org.mitre.oval:tst:139599"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.35-1.13.7.1.el5_11" test_ref="oval:org.mitre.oval:tst:140190"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.35-1.13.7.1.el5_11" test_ref="oval:org.mitre.oval:tst:139601"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="java-1.6.0-openjdk-debuginfo is earlier than 1:1.6.0.35-1.13.7.1.el5_11" test_ref="oval:org.mitre.oval:tst:139980"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.35-1.13.7.1.el6_6" test_ref="oval:org.mitre.oval:tst:140224"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.35-1.13.7.1.el6_6" test_ref="oval:org.mitre.oval:tst:140018"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.35-1.13.7.1.el6_6" test_ref="oval:org.mitre.oval:tst:140221"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.35-1.13.7.1.el6_6" test_ref="oval:org.mitre.oval:tst:139857"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.35-1.13.7.1.el6_6" test_ref="oval:org.mitre.oval:tst:139697"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="java-1.6.0-openjdk-debuginfo is earlier than 1:1.6.0.35-1.13.7.1.el6_6" test_ref="oval:org.mitre.oval:tst:140057"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.35-1.13.7.1.el7_1" test_ref="oval:org.mitre.oval:tst:139981"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.35-1.13.7.1.el7_1" test_ref="oval:org.mitre.oval:tst:139711"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.35-1.13.7.1.el7_1" test_ref="oval:org.mitre.oval:tst:140101"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.35-1.13.7.1.el7_1" test_ref="oval:org.mitre.oval:tst:140204"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.35-1.13.7.1.el7_1" test_ref="oval:org.mitre.oval:tst:140123"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criterion comment="java-1.6.0-openjdk-debuginfo is earlier than 1:1.6.0.35-1.13.7.1.el7_1" test_ref="oval:org.mitre.oval:tst:140122"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29137" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:1029 -- cups security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1029.html" ref_id="RHSA-2008:1029"/>
        <reference source="CESA-2008:1029" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-December/015493.html" ref_id="CESA-2008:1029-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5183" ref_id="CVE-2008-5183"/>
        <description>Updated cups packages that fix a security issue are now available for Red
Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red Hat Security Response Team.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:10.819-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:11.246-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:00.531-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="cups-devel is earlier than 1:1.2.4-11.18.el5_2.3" test_ref="oval:org.mitre.oval:tst:140300"/>
          <criterion comment="cups is earlier than 1:1.2.4-11.18.el5_2.3" test_ref="oval:org.mitre.oval:tst:140311"/>
          <criterion comment="cups-libs is earlier than 1:1.2.4-11.18.el5_2.3" test_ref="oval:org.mitre.oval:tst:140521"/>
          <criterion comment="cups-lpd is earlier than 1:1.2.4-11.18.el5_2.3" test_ref="oval:org.mitre.oval:tst:140673"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29134" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1209 -- curl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>curl</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1209.html" ref_id="RHSA-2009:1209"/>
        <reference source="CESA-2009:1209" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-August/016076.html" ref_id="CESA-2009:1209-CentOS 3"/>
        <reference source="CESA-2009:1209" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-August/016095.html" ref_id="CESA-2009:1209-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2417" ref_id="CVE-2009-2417"/>
        <description>Updated curl packages that fix security issues are now available for Red
Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and Dict
servers, using any of the supported protocols. cURL is designed to work
without user interaction or any kind of interactivity.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:34.810-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:10.108-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:59.269-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="curl-devel is earlier than 0:7.15.5-2.1.el5_3.5" test_ref="oval:org.mitre.oval:tst:140825"/>
            <criterion comment="curl is earlier than 0:7.15.5-2.1.el5_3.5" test_ref="oval:org.mitre.oval:tst:140810"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="curl is earlier than 0:7.10.6-10.rhel3" test_ref="oval:org.mitre.oval:tst:140420"/>
            <criterion comment="curl-devel is earlier than 0:7.10.6-10.rhel3" test_ref="oval:org.mitre.oval:tst:140855"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="curl is earlier than 0:7.12.1-11.1.el4_8.1" test_ref="oval:org.mitre.oval:tst:140863"/>
            <criterion comment="curl-devel is earlier than 0:7.12.1-11.1.el4_8.1" test_ref="oval:org.mitre.oval:tst:140551"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29133" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0818 -- hplip security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>hplip</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0818.html" ref_id="RHSA-2008:0818"/>
        <reference source="CESA-2008:0818" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-August/015189.html" ref_id="CESA-2008:0818-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2940" ref_id="CVE-2008-2940"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2941" ref_id="CVE-2008-2941"/>
        <description>Updated hplip packages that fix various security issues are now available
for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The hplip (Hewlett-Packard Linux Imaging and Printing) packages provide
drivers for Hewlett-Packard printers and multifunction peripherals.
A flaw was discovered in the hplip alert-mailing functionality. A local
attacker could elevate their privileges by using specially-crafted packets
to trigger alert mails, which are sent by the root account. (CVE-2008-2940)
A flaw was discovered in the hpssd message parser. By sending
specially-crafted packets, a local attacker could cause a denial of
service, stopping the hpssd process. (CVE-2008-2941)
Users of hplip should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:50.664-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:09.890-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:58.810-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="hpijs is earlier than 0:1.6.7-4.1.el5_2.4" test_ref="oval:org.mitre.oval:tst:139153"/>
            <criterion comment="hplip is earlier than 0:1.6.7-4.1.el5_2.4" test_ref="oval:org.mitre.oval:tst:139170"/>
            <criterion comment="libsane-hpaio is earlier than 0:1.6.7-4.1.el5_2.4" test_ref="oval:org.mitre.oval:tst:139324"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postfix is earlier than 0:2.3.3-2.1.el5_2" test_ref="oval:org.mitre.oval:tst:139326"/>
            <criterion comment="postfix-pflogsumm is earlier than 0:2.3.3-2.1.el5_2" test_ref="oval:org.mitre.oval:tst:138478"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29129" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0885 -- kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0885.html" ref_id="RHSA-2008:0885"/>
        <reference source="CESA-2008:0885" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-September/015273.html" ref_id="CESA-2008:0885-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6417" ref_id="CVE-2007-6417"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6716" ref_id="CVE-2007-6716"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2931" ref_id="CVE-2008-2931"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3272" ref_id="CVE-2008-3272"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3275" ref_id="CVE-2008-3275"/>
        <description>Updated kernel packages that fix various security issues and several bugs
are now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The kernel packages contain the Linux kernel, the core of any Linux
operating system.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:14.598-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:09.504-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:58.114-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:139084"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:139263"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:139270"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:138408"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:139083"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:139088"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:138876"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:139248"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:139093"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:139028"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29125" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1130 -- kdegraphics security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kdegraphics</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1130.html" ref_id="RHSA-2009:1130"/>
        <reference source="CESA-2009:1130" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-June/016009.html" ref_id="CESA-2009:1130-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0945" ref_id="CVE-2009-0945"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1709" ref_id="CVE-2009-1709"/>
        <description>Updated kdegraphics packages that fix two security issues are now available
for Red Hat Enterprise Linux 5.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
The kdegraphics packages contain applications for the K Desktop Environment
(KDE). Scalable Vector Graphics (SVG) is an XML-based language to describe
vector images. KSVG is a framework aimed at implementing the latest W3C SVG
specifications.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:44.200-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:08.886-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:57.718-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-13.el5_3" test_ref="oval:org.mitre.oval:tst:139665"/>
          <criterion comment="kdegraphics is earlier than 7:3.5.4-13.el5_3" test_ref="oval:org.mitre.oval:tst:139130"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29116" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0976 -- thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0976.html" ref_id="RHSA-2008:0976"/>
        <reference source="CESA-2008:0976" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-November/015428.html" ref_id="CESA-2008:0976-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5012" ref_id="CVE-2008-5012"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5014" ref_id="CVE-2008-5014"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5016" ref_id="CVE-2008-5016"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5017" ref_id="CVE-2008-5017"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5018" ref_id="CVE-2008-5018"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5021" ref_id="CVE-2008-5021"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5022" ref_id="CVE-2008-5022"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5024" ref_id="CVE-2008-5024"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5052" ref_id="CVE-2008-5052"/>
        <description>Updated thunderbird packages that fix several security issues are now
available for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Mozilla Thunderbird is a standalone mail and newsgroup client.
Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2008-5014, CVE-2008-5016, CVE-2008-5017, CVE-2008-5018,
CVE-2008-5021)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:34:44.854-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:07.151-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:57.036-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="thunderbird is earlier than 0:1.5.0.12-17.el4" test_ref="oval:org.mitre.oval:tst:139039"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.18-1.el5" test_ref="oval:org.mitre.oval:tst:139120"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.18-1.el5.centos" test_ref="oval:org.mitre.oval:tst:139082"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29111" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1426 -- openoffice.org security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <product>openoffice.org</product>
          <product>openoffice.org2</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1426.html" ref_id="RHSA-2009:1426"/>
        <reference source="CESA-2009:1426" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-September/016121.html" ref_id="CESA-2009:1426-CentOS 3"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0200" ref_id="CVE-2009-0200"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0201" ref_id="CVE-2009-0201"/>
        <description>Updated openoffice.org packages that correct security issues are now
available for Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet, presentation manager,
formula editor, and a drawing program.
An integer underflow flaw and a boundary error flaw, both possibly leading
to a heap-based buffer overflow, were found in the way OpenOffice.org
parses certain records in Microsoft Word documents. An attacker could
create a specially-crafted Microsoft Word document, which once opened by an
unsuspecting user, could cause OpenOffice.org to crash or, potentially,
execute arbitrary code with the permissions of the user running
OpenOffice.org. (CVE-2009-0200, CVE-2009-0201)
All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported patches to correct these issues. All
running instances of OpenOffice.org applications must be restarted for
this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:39.295-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:05.577-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:55.712-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openoffice.org-sdk is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:138912"/>
            <criterion comment="openoffice.org-sdk-doc is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139161"/>
            <criterion comment="openoffice.org-base is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:138681"/>
            <criterion comment="openoffice.org-calc is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139322"/>
            <criterion comment="openoffice.org-core is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139233"/>
            <criterion comment="openoffice.org-draw is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139141"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139319"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139401"/>
            <criterion comment="openoffice.org-headless is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139295"/>
            <criterion comment="openoffice.org-impress is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139417"/>
            <criterion comment="openoffice.org-javafilter is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139483"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139123"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:138759"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139172"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139364"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:138675"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139107"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139202"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139187"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139315"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139434"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139449"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139353"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139371"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139423"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:138837"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139212"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139431"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139258"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139332"/>
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139473"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139142"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139432"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139455"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139274"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:138625"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139074"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139325"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139185"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139573"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139369"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139519"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139203"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139342"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139180"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139232"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139118"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139338"/>
            <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139436"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139607"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139617"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139458"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139569"/>
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139546"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139403"/>
            <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139568"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139132"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:138967"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139379"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139321"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139450"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139344"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139243"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139503"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139523"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139279"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139411"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139285"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139350"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139544"/>
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139604"/>
            <criterion comment="openoffice.org-math is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139606"/>
            <criterion comment="openoffice.org-pyuno is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139388"/>
            <criterion comment="openoffice.org-testtools is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:138887"/>
            <criterion comment="openoffice.org-writer is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:139154"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 1:2.3.0-6.11.el5_4.1" test_ref="oval:org.mitre.oval:tst:138655"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openoffice.org is earlier than 1:1.1.2-44.2.0.EL3" test_ref="oval:org.mitre.oval:tst:139508"/>
            <criterion comment="openoffice.org-i18n is earlier than 1:1.1.2-44.2.0.EL3" test_ref="oval:org.mitre.oval:tst:139553"/>
            <criterion comment="openoffice.org-libs is earlier than 1:1.1.2-44.2.0.EL3" test_ref="oval:org.mitre.oval:tst:139641"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openoffice.org is earlier than 1:1.1.5-10.6.0.7.EL4.1" test_ref="oval:org.mitre.oval:tst:138975"/>
            <criterion comment="openoffice.org-i18n is earlier than 1:1.1.5-10.6.0.7.EL4.1" test_ref="oval:org.mitre.oval:tst:139539"/>
            <criterion comment="openoffice.org-kde is earlier than 1:1.1.5-10.6.0.7.EL4.1" test_ref="oval:org.mitre.oval:tst:139162"/>
            <criterion comment="openoffice.org-libs is earlier than 1:1.1.5-10.6.0.7.EL4.1" test_ref="oval:org.mitre.oval:tst:139571"/>
            <criterion comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139383"/>
            <criterion comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:138969"/>
            <criterion comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139567"/>
            <criterion comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139646"/>
            <criterion comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139654"/>
            <criterion comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139576"/>
            <criterion comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139474"/>
            <criterion comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139506"/>
            <criterion comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139435"/>
            <criterion comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139517"/>
            <criterion comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139405"/>
            <criterion comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139376"/>
            <criterion comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139635"/>
            <criterion comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139126"/>
            <criterion comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139608"/>
            <criterion comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139640"/>
            <criterion comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139380"/>
            <criterion comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139514"/>
            <criterion comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139633"/>
            <criterion comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139577"/>
            <criterion comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139596"/>
            <criterion comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:138960"/>
            <criterion comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139323"/>
            <criterion comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139366"/>
            <criterion comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:138928"/>
            <criterion comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:138806"/>
            <criterion comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139598"/>
            <criterion comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:138782"/>
            <criterion comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139201"/>
            <criterion comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139456"/>
            <criterion comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139619"/>
            <criterion comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139354"/>
            <criterion comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139419"/>
            <criterion comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139422"/>
            <criterion comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:138976"/>
            <criterion comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139337"/>
            <criterion comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139643"/>
            <criterion comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139559"/>
            <criterion comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139022"/>
            <criterion comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139312"/>
            <criterion comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139220"/>
            <criterion comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139147"/>
            <criterion comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139112"/>
            <criterion comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139105"/>
            <criterion comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139649"/>
            <criterion comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139320"/>
            <criterion comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139525"/>
            <criterion comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139554"/>
            <criterion comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139530"/>
            <criterion comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139516"/>
            <criterion comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139610"/>
            <criterion comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139557"/>
            <criterion comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139648"/>
            <criterion comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139363"/>
            <criterion comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139339"/>
            <criterion comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139580"/>
            <criterion comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139316"/>
            <criterion comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.6.0.1" test_ref="oval:org.mitre.oval:tst:139625"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29110" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1060 -- pidgin security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1060.html" ref_id="RHSA-2009:1060"/>
        <reference source="CESA-2009:1060" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-May/015891.html" ref_id="CESA-2009:1060-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1373" ref_id="CVE-2009-1373"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1374" ref_id="CVE-2009-1374"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1375" ref_id="CVE-2009-1375"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1376" ref_id="CVE-2009-1376"/>
        <description>Updated pidgin packages that fix several security issues are now available
for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.
A buffer overflow flaw was found in the way Pidgin initiates file transfers
when using the Extensible Messaging and Presence Protocol (XMPP). If a
Pidgin client initiates a file transfer, and the remote target sends a
malformed response, it could cause Pidgin to crash or, potentially, execute
arbitrary code with the permissions of the user running Pidgin. This flaw
only affects accounts using XMPP, such as Jabber and Google Talk.
(CVE-2009-1373)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:42.742-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:05.088-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:55.098-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="finch-devel is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:139391"/>
            <criterion comment="libpurple-devel is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:139367"/>
            <criterion comment="pidgin-devel is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:139158"/>
            <criterion comment="finch is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:139335"/>
            <criterion comment="libpurple is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:139481"/>
            <criterion comment="libpurple-perl is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:139616"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:139476"/>
            <criterion comment="pidgin is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:139634"/>
            <criterion comment="pidgin-perl is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:139681"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="finch is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:139278"/>
            <criterion comment="finch-devel is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:139587"/>
            <criterion comment="libpurple is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:139489"/>
            <criterion comment="libpurple-devel is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:139196"/>
            <criterion comment="libpurple-perl is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:139628"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:139586"/>
            <criterion comment="pidgin is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:139605"/>
            <criterion comment="pidgin-devel is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:139538"/>
            <criterion comment="pidgin-perl is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:139400"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29109" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1620 -- bind security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1620.html" ref_id="RHSA-2009:1620"/>
        <reference source="CESA-2009:1620" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-December/016364.html" ref_id="CESA-2009:1620-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4022" ref_id="CVE-2009-4022"/>
        <description>Updated bind packages that fix one security issue are now available for
Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:37:20.957-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:04.940-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:54.828-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind-chroot is earlier than 30:9.3.6-4.P1.el5_4.1" test_ref="oval:org.mitre.oval:tst:139733"/>
          <criterion comment="bind-devel is earlier than 30:9.3.6-4.P1.el5_4.1" test_ref="oval:org.mitre.oval:tst:139884"/>
          <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-4.P1.el5_4.1" test_ref="oval:org.mitre.oval:tst:140262"/>
          <criterion comment="caching-nameserver is earlier than 30:9.3.6-4.P1.el5_4.1" test_ref="oval:org.mitre.oval:tst:139792"/>
          <criterion comment="bind is earlier than 30:9.3.6-4.P1.el5_4.1" test_ref="oval:org.mitre.oval:tst:139719"/>
          <criterion comment="bind-libs is earlier than 30:9.3.6-4.P1.el5_4.1" test_ref="oval:org.mitre.oval:tst:140118"/>
          <criterion comment="bind-sdb is earlier than 30:9.3.6-4.P1.el5_4.1" test_ref="oval:org.mitre.oval:tst:140263"/>
          <criterion comment="bind-utils is earlier than 30:9.3.6-4.P1.el5_4.1" test_ref="oval:org.mitre.oval:tst:140025"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29103" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1138 -- openswan security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openswan</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1138.html" ref_id="RHSA-2009:1138"/>
        <reference source="CESA-2009:1138" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-July/016021.html" ref_id="CESA-2009:1138-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2185" ref_id="CVE-2009-2185"/>
        <description>Updated openswan packages that fix multiple security issues are now
available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
Openswan is a free implementation of Internet Protocol Security (IPsec)
and Internet Key Exchange (IKE). IPsec uses strong cryptography to provide
both authentication and encryption services. These services allow you to
build secure tunnels through untrusted networks. Everything passing through
the untrusted network is encrypted by the IPsec gateway machine, and
decrypted by the gateway at the other end of the tunnel. The resulting
tunnel is a virtual private network (VPN).</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:32.102-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:04.727-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:54.631-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openswan is earlier than 0:2.6.14-1.el5_3.3" test_ref="oval:org.mitre.oval:tst:141031"/>
          <criterion comment="openswan-doc is earlier than 0:2.6.14-1.el5_3.3" test_ref="oval:org.mitre.oval:tst:141051"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29100" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1139 -- pidgin security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1139.html" ref_id="RHSA-2009:1139"/>
        <reference source="CESA-2009:1139" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-July/016023.html" ref_id="CESA-2009:1139-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1889" ref_id="CVE-2009-1889"/>
        <description>Updated pidgin packages that fix one security issue and one bug are now
available for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously. The AOL
Open System for CommunicAtion in Realtime (OSCAR) protocol is used by the
AOL ICQ and AIM instant messaging systems.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:54">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:45.026-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:04.513-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:54.346-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="finch-devel is earlier than 0:2.5.8-1.el5" test_ref="oval:org.mitre.oval:tst:139585"/>
            <criterion comment="libpurple-devel is earlier than 0:2.5.8-1.el5" test_ref="oval:org.mitre.oval:tst:139575"/>
            <criterion comment="pidgin-devel is earlier than 0:2.5.8-1.el5" test_ref="oval:org.mitre.oval:tst:139614"/>
            <criterion comment="finch is earlier than 0:2.5.8-1.el5" test_ref="oval:org.mitre.oval:tst:139522"/>
            <criterion comment="libpurple is earlier than 0:2.5.8-1.el5" test_ref="oval:org.mitre.oval:tst:139457"/>
            <criterion comment="libpurple-perl is earlier than 0:2.5.8-1.el5" test_ref="oval:org.mitre.oval:tst:139566"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.5.8-1.el5" test_ref="oval:org.mitre.oval:tst:139630"/>
            <criterion comment="pidgin is earlier than 0:2.5.8-1.el5" test_ref="oval:org.mitre.oval:tst:139676"/>
            <criterion comment="pidgin-perl is earlier than 0:2.5.8-1.el5" test_ref="oval:org.mitre.oval:tst:139510"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="finch is earlier than 0:2.5.8-1.el4" test_ref="oval:org.mitre.oval:tst:139612"/>
            <criterion comment="finch-devel is earlier than 0:2.5.8-1.el4" test_ref="oval:org.mitre.oval:tst:139365"/>
            <criterion comment="libpurple is earlier than 0:2.5.8-1.el4" test_ref="oval:org.mitre.oval:tst:139182"/>
            <criterion comment="libpurple-devel is earlier than 0:2.5.8-1.el4" test_ref="oval:org.mitre.oval:tst:139217"/>
            <criterion comment="libpurple-perl is earlier than 0:2.5.8-1.el4" test_ref="oval:org.mitre.oval:tst:139407"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.5.8-1.el4" test_ref="oval:org.mitre.oval:tst:139155"/>
            <criterion comment="pidgin is earlier than 0:2.5.8-1.el4" test_ref="oval:org.mitre.oval:tst:138936"/>
            <criterion comment="pidgin-devel is earlier than 0:2.5.8-1.el4" test_ref="oval:org.mitre.oval:tst:139122"/>
            <criterion comment="pidgin-perl is earlier than 0:2.5.8-1.el4" test_ref="oval:org.mitre.oval:tst:138984"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29098" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0267 -- sudo security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0267.html" ref_id="RHSA-2009:0267"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0034" ref_id="CVE-2009-0034"/>
        <description>An updated sudo package to fix a security issue is now available for Red
Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root with logging.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:20.358-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:04.018-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:54.166-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="sudo is earlier than 0:1.6.9p17-3.el5_3.1" test_ref="oval:org.mitre.oval:tst:140379"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29091" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1061 -- freetype security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1061.html" ref_id="RHSA-2009:1061"/>
        <reference source="CESA-2009:1061" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-May/015894.html" ref_id="CESA-2009:1061-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0946" ref_id="CVE-2009-0946"/>
        <description>Updated freetype packages that fix various security issues are now
available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. These packages provide the FreeType 2 font engine.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:17.608-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:02.885-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:53.522-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="freetype-demos is earlier than 0:2.2.1-21.el5_3" test_ref="oval:org.mitre.oval:tst:140797"/>
          <criterion comment="freetype-devel is earlier than 0:2.2.1-21.el5_3" test_ref="oval:org.mitre.oval:tst:141027"/>
          <criterion comment="freetype is earlier than 0:2.2.1-21.el5_3" test_ref="oval:org.mitre.oval:tst:141074"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29090" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0907 -- pam_krb5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>pam_krb5</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0907.html" ref_id="RHSA-2008:0907"/>
        <reference source="CESA-2008:0907" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-October/015305.html" ref_id="CESA-2008:0907-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3825" ref_id="CVE-2008-3825"/>
        <description>An updated pam_krb5 package that fixes a security issue is now available
for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The pam_krb5 module allows Pluggable Authentication Modules (PAM) aware
applications to use Kerberos to verify user identities by obtaining user
credentials at log in time.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:48.759-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:02.760-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:53.314-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="pam_krb5 is earlier than 0:2.2.14-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:139085"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29088" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0313 -- wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0313.html" ref_id="RHSA-2009:0313"/>
        <reference source="CESA-2009:0313" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-March/015651.html" ref_id="CESA-2009:0313-CentOS 3"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4680" ref_id="CVE-2008-4680"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4681" ref_id="CVE-2008-4681"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4682" ref_id="CVE-2008-4682"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4683" ref_id="CVE-2008-4683"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4684" ref_id="CVE-2008-4684"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4685" ref_id="CVE-2008-4685"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5285" ref_id="CVE-2008-5285"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6472" ref_id="CVE-2008-6472"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0599" ref_id="CVE-2009-0599"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0600" ref_id="CVE-2009-0600"/>
        <description>Updated wireshark packages that fix several security issues are now
available for Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.
Multiple buffer overflow flaws were found in Wireshark. If Wireshark read
a malformed packet off a network or opened a malformed dump file, it could
crash or, possibly, execute arbitrary code as the user running Wireshark.
(CVE-2008-4683, CVE-2009-0599)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:39:57.291-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:02.131-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:52.616-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:140214"/>
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:140245"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="wireshark is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:140361"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:140273"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:140181"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:140440"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29084" version="3" class="patch">
      <metadata>
        <title>RHSA-2015:0807 -- java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2015-0807.html" ref_id="RHSA-2015:0807"/>
        <reference source="CESA-2015:0807" ref_url="http://lists.centos.org/pipermail/centos-announce/2015-April/021075.html" ref_id="CESA-2015:0807"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1080" ref_id="CVE-2005-1080"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0460" ref_id="CVE-2015-0460"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0469" ref_id="CVE-2015-0469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0477" ref_id="CVE-2015-0477"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0478" ref_id="CVE-2015-0478"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0480" ref_id="CVE-2015-0480"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0488" ref_id="CVE-2015-0488"/>
        <description>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.
An off-by-one flaw, leading to a buffer overflow, was found in the font
parsing code in the 2D component in OpenJDK. A specially crafted font file
could possibly cause the Java Virtual Machine to execute arbitrary code,
allowing an untrusted Java application or applet to bypass Java sandbox
restrictions. (CVE-2015-0469)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:37:29.118-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:01.629-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:52.411-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.79-2.5.5.2.el5_11" test_ref="oval:org.mitre.oval:tst:140036"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.79-2.5.5.2.el5_11" test_ref="oval:org.mitre.oval:tst:140197"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.79-2.5.5.2.el5_11" test_ref="oval:org.mitre.oval:tst:140235"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.79-2.5.5.2.el5_11" test_ref="oval:org.mitre.oval:tst:139563"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.79-2.5.5.2.el5_11" test_ref="oval:org.mitre.oval:tst:139773"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="java-1.7.0-openjdk-debuginfo is earlier than 1:1.7.0.79-2.5.5.2.el5_11" test_ref="oval:org.mitre.oval:tst:139564"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29079" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0479 -- perl-DBD-Pg security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>perl-DBD-Pg</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0479.html" ref_id="RHSA-2009:0479"/>
        <reference source="CESA-2009:0479" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-May/015877.html" ref_id="CESA-2009:0479-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0663" ref_id="CVE-2009-0663"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1341" ref_id="CVE-2009-1341"/>
        <description>An updated perl-DBD-Pg package that fixes two security issues is now
available for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Perl DBI is a database access Application Programming Interface (API) for
the Perl language. perl-DBD-Pg allows Perl applications to access
PostgreSQL database servers.
A heap-based buffer overflow flaw was discovered in the pg_getline function
implementation. If the pg_getline or getline functions read large,
untrusted records from a database, it could cause an application using
these functions to crash or, possibly, execute arbitrary code.
(CVE-2009-0663)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:38.194-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:01.196-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:52.135-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="perl-DBD-Pg is earlier than 0:1.49-2.el5_3.1" test_ref="oval:org.mitre.oval:tst:141018"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29077" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1204 -- apr and apr-util security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>apr</product>
          <product>apr-util</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1204.html" ref_id="RHSA-2009:1204"/>
        <reference source="CESA-2009:1204" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-August/016072.html" ref_id="CESA-2009:1204-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2412" ref_id="CVE-2009-2412"/>
        <description>Updated apr and apr-util packages that fix multiple security issues are now
available for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The Apache Portable Runtime (APR) is a portability library used by the
Apache HTTP Server and other projects. It aims to provide a free library
of C data structures and routines.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:03">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:10.186-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:00.779-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:51.664-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="apr-devel is earlier than 0:1.2.7-11.el5_3.1" test_ref="oval:org.mitre.oval:tst:139952"/>
            <criterion comment="apr-util-devel is earlier than 0:1.2.7-7.el5_3.2" test_ref="oval:org.mitre.oval:tst:140848"/>
            <criterion comment="apr is earlier than 0:1.2.7-11.el5_3.1" test_ref="oval:org.mitre.oval:tst:140648"/>
            <criterion comment="apr-docs is earlier than 0:1.2.7-11.el5_3.1" test_ref="oval:org.mitre.oval:tst:140494"/>
            <criterion comment="apr-util is earlier than 0:1.2.7-7.el5_3.2" test_ref="oval:org.mitre.oval:tst:140737"/>
            <criterion comment="apr-util-docs is earlier than 0:1.2.7-7.el5_3.2" test_ref="oval:org.mitre.oval:tst:140708"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="apr is earlier than 0:0.9.4-24.9.el4_8.2" test_ref="oval:org.mitre.oval:tst:140538"/>
            <criterion comment="apr-devel is earlier than 0:0.9.4-24.9.el4_8.2" test_ref="oval:org.mitre.oval:tst:140814"/>
            <criterion comment="apr-util is earlier than 0:0.9.4-22.el4_8.2" test_ref="oval:org.mitre.oval:tst:140804"/>
            <criterion comment="apr-util-devel is earlier than 0:0.9.4-22.el4_8.2" test_ref="oval:org.mitre.oval:tst:140951"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29069" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0939 -- openoffice.org security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>openoffice.org</product>
          <product>openoffice.org2</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0939.html" ref_id="RHSA-2008:0939"/>
        <reference source="CESA-2008:0939" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-November/015371.html" ref_id="CESA-2008:0939-CentOS 3"/>
        <reference source="CESA-2008:0939" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-November/015383.html" ref_id="CESA-2008:0939-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2237" ref_id="CVE-2008-2237"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2238" ref_id="CVE-2008-2238"/>
        <description>Updated openoffice.org packages that correct security issues are now
available for Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:34:43.842-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:57.815-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:49.882-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openoffice.org-sdk is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139499"/>
            <criterion comment="openoffice.org-sdk-doc is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139438"/>
            <criterion comment="openoffice.org-base is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139445"/>
            <criterion comment="openoffice.org-calc is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139370"/>
            <criterion comment="openoffice.org-core is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139063"/>
            <criterion comment="openoffice.org-draw is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139600"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139226"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139687"/>
            <criterion comment="openoffice.org-headless is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139644"/>
            <criterion comment="openoffice.org-impress is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139267"/>
            <criterion comment="openoffice.org-javafilter is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139631"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139334"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139372"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139296"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139556"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:138726"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139532"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139164"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139027"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139659"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139622"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139680"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139684"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139626"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139655"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139537"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139650"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139454"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139722"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139349"/>
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:138784"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139283"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139156"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139336"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139397"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139683"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139507"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139708"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139709"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139696"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139755"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139766"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139595"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139703"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139661"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139464"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139685"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139747"/>
            <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139775"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139771"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139769"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139779"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139706"/>
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139560"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139106"/>
            <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139015"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:138950"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139570"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139686"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139498"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139671"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139768"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139749"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139188"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139428"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139521"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139756"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139721"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139638"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139412"/>
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139782"/>
            <criterion comment="openoffice.org-math is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139528"/>
            <criterion comment="openoffice.org-pyuno is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139119"/>
            <criterion comment="openoffice.org-testtools is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139698"/>
            <criterion comment="openoffice.org-writer is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139359"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 1:2.3.0-6.5.4.el5_2" test_ref="oval:org.mitre.oval:tst:139025"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openoffice.org is earlier than 1:1.1.2-43.2.0.EL3" test_ref="oval:org.mitre.oval:tst:139724"/>
            <criterion comment="openoffice.org-i18n is earlier than 1:1.1.2-43.2.0.EL3" test_ref="oval:org.mitre.oval:tst:138956"/>
            <criterion comment="openoffice.org-libs is earlier than 1:1.1.2-43.2.0.EL3" test_ref="oval:org.mitre.oval:tst:139754"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openoffice.org is earlier than 1:1.1.5-10.6.0.7.EL4" test_ref="oval:org.mitre.oval:tst:139731"/>
            <criterion comment="openoffice.org-i18n is earlier than 1:1.1.5-10.6.0.7.EL4" test_ref="oval:org.mitre.oval:tst:139534"/>
            <criterion comment="openoffice.org-kde is earlier than 1:1.1.5-10.6.0.7.EL4" test_ref="oval:org.mitre.oval:tst:139492"/>
            <criterion comment="openoffice.org-libs is earlier than 1:1.1.5-10.6.0.7.EL4" test_ref="oval:org.mitre.oval:tst:139478"/>
            <criterion comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139547"/>
            <criterion comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:138857"/>
            <criterion comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139821"/>
            <criterion comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139618"/>
            <criterion comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139211"/>
            <criterion comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139410"/>
            <criterion comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139688"/>
            <criterion comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139858"/>
            <criterion comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:138858"/>
            <criterion comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139673"/>
            <criterion comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139813"/>
            <criterion comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139780"/>
            <criterion comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139827"/>
            <criterion comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139846"/>
            <criterion comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139589"/>
            <criterion comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139712"/>
            <criterion comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139802"/>
            <criterion comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139695"/>
            <criterion comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139527"/>
            <criterion comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139715"/>
            <criterion comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139762"/>
            <criterion comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139825"/>
            <criterion comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139705"/>
            <criterion comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139664"/>
            <criterion comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139836"/>
            <criterion comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139752"/>
            <criterion comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139774"/>
            <criterion comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139637"/>
            <criterion comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139790"/>
            <criterion comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:138978"/>
            <criterion comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139682"/>
            <criterion comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139389"/>
            <criterion comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139691"/>
            <criterion comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139817"/>
            <criterion comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139297"/>
            <criterion comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139282"/>
            <criterion comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139748"/>
            <criterion comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139545"/>
            <criterion comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139753"/>
            <criterion comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139831"/>
            <criterion comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:138925"/>
            <criterion comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139807"/>
            <criterion comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139190"/>
            <criterion comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139658"/>
            <criterion comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139668"/>
            <criterion comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139491"/>
            <criterion comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139907"/>
            <criterion comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139495"/>
            <criterion comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139859"/>
            <criterion comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139737"/>
            <criterion comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139191"/>
            <criterion comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139531"/>
            <criterion comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139486"/>
            <criterion comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139318"/>
            <criterion comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139750"/>
            <criterion comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139163"/>
            <criterion comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139702"/>
            <criterion comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.6.0" test_ref="oval:org.mitre.oval:tst:139759"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29068" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0336 -- glib2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>glib2</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0336.html" ref_id="RHSA-2009:0336"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4316" ref_id="CVE-2008-4316"/>
        <description>Updated glib2 packages that fix several security issues are now available
for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
GLib is the low-level core library that forms the basis for projects such
as GTK+ and GNOME. It provides data structure handling for C, portability
wrappers, and interfaces for such runtime functionality as an event loop,
threads, dynamic loading, and an object system.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:53">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:08.823-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:57.680-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:49.587-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glib2-devel is earlier than 0:2.12.3-4.el5_3.1" test_ref="oval:org.mitre.oval:tst:140252"/>
          <criterion comment="glib2 is earlier than 0:2.12.3-4.el5_3.1" test_ref="oval:org.mitre.oval:tst:140370"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29066" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0597 -- firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>devhelp</product>
          <product>firefox</product>
          <product>nspluginwrapper</product>
          <product>xulrunner</product>
          <product>yelp</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0597.html" ref_id="RHSA-2008:0597"/>
        <reference source="CESA-2008:0597" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-July/015135.html" ref_id="CESA-2008:0597-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2785" ref_id="CVE-2008-2785"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2933" ref_id="CVE-2008-2933"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3198" ref_id="CVE-2008-3198"/>
        <description>Updated firefox packages that fix various security issues are now available
for Red Hat Enterprise Linux 5.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
The nspluginwrapper package has been added to this advisory to satisfy a
missing package dependency issue.
Mozilla Firefox is an open source Web browser.
An integer overflow flaw was found in the way Firefox displayed certain web
content. A malicious web site could cause Firefox to crash, or execute
arbitrary code with the permissions of the user running Firefox.
(CVE-2008-2785)
A flaw was found in the way Firefox handled certain command line URLs. If
another application passed Firefox a malformed URL, it could result in
Firefox executing local malicious content with chrome privileges.
(CVE-2008-2933)
All firefox users should upgrade to these updated packages, which contain
Firefox 3.0.1 that corrects these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:30.828-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:57.219-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:49.337-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="devhelp-devel is earlier than 0:0.12-18.el5" test_ref="oval:org.mitre.oval:tst:139065"/>
          <criterion comment="xulrunner-devel is earlier than 0:1.9.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:139157"/>
          <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:138992"/>
          <criterion comment="devhelp is earlier than 0:0.12-18.el5" test_ref="oval:org.mitre.oval:tst:139327"/>
          <criterion comment="firefox is earlier than 0:3.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:139309"/>
          <criterion comment="nspluginwrapper is earlier than 0:0.9.91.5-22.el5" test_ref="oval:org.mitre.oval:tst:139129"/>
          <criterion comment="xulrunner is earlier than 0:1.9.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:139303"/>
          <criterion comment="yelp is earlier than 0:2.16.0-20.el5" test_ref="oval:org.mitre.oval:tst:139151"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29052" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1341 -- cman security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>cman</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1341.html" ref_id="RHSA-2009:1341"/>
        <reference source="CESA-2009:1341" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-September/016155.html" ref_id="CESA-2009:1341-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4579" ref_id="CVE-2008-4579"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6552" ref_id="CVE-2008-6552"/>
        <description>Updated cman packages that fix several security issues, various bugs, and
add enhancements are now available for Red Hat Enterprise Linux 5.
This update has been rated as having low security impact by the Red Hat
Security Response Team.
The Cluster Manager (cman) utility provides services for managing a Linux
cluster.
Multiple insecure temporary file use flaws were found in fence_apc_snmp and
ccs_tool. A local attacker could use these flaws to overwrite an arbitrary
file writable by a victim running those utilities (typically root) with
the output of the utilities via a symbolic link attack. (CVE-2008-4579,
CVE-2008-6552)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:54">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:28.681-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:56.309-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:48.909-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="cman is earlier than 0:2.0.115-1.el5" test_ref="oval:org.mitre.oval:tst:140609"/>
          <criterion comment="cman-devel is earlier than 0:2.0.115-1.el5" test_ref="oval:org.mitre.oval:tst:140755"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29047" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1615 -- xerces-j2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>xerces-j2</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1615.html" ref_id="RHSA-2009:1615"/>
        <reference source="CESA-2009:1615" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-December/016368.html" ref_id="CESA-2009:1615-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2625" ref_id="CVE-2009-2625"/>
        <description>Updated xerces-j2 packages that fix a security issue are now available for
Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The xerces-j2 packages provide the Apache Xerces2 Java Parser, a
high-performance XML parser. A Document Type Definition (DTD) defines the
legal syntax (and also which elements can be used) for certain types of
files, such as XML files.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:37:23.807-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:55.838-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:48.713-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="xerces-j2-demo is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:140271"/>
          <criterion comment="xerces-j2-javadoc-apis is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:140265"/>
          <criterion comment="xerces-j2-javadoc-impl is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:140176"/>
          <criterion comment="xerces-j2-javadoc-other is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:139866"/>
          <criterion comment="xerces-j2-javadoc-xni is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:139894"/>
          <criterion comment="xerces-j2 is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:139791"/>
          <criterion comment="xerces-j2-scripts is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:139583"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29046" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1536 -- pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1536.html" ref_id="RHSA-2009:1536"/>
        <reference source="CESA-2009:1536" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-October/016266.html" ref_id="CESA-2009:1536-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3615" ref_id="CVE-2009-3615"/>
        <description>Updated pidgin packages that fix a security issue are now available for Red
Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously. The AOL
Open System for Communication in Realtime (OSCAR) protocol is used by the
AOL ICQ and AIM instant messaging systems.
An invalid pointer dereference bug was found in the way the Pidgin OSCAR
protocol implementation processed lists of contacts. A remote attacker
could send a specially-crafted contact list to a user running Pidgin,
causing Pidgin to crash. (CVE-2009-3615)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:33">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:45.805-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:55.612-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:48.354-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="finch-devel is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:139223"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:139014"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:139333"/>
            <criterion comment="finch is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:139439"/>
            <criterion comment="libpurple is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:139487"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:138954"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:139125"/>
            <criterion comment="pidgin is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:139414"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:139186"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="finch is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:139361"/>
            <criterion comment="finch-devel is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:139470"/>
            <criterion comment="libpurple is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:139281"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:139346"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:139036"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:139413"/>
            <criterion comment="pidgin is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:139398"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:139289"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:139424"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29045" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0256 -- firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>nss</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0256.html" ref_id="RHSA-2009:0256"/>
        <reference source="CESA-2009:0256" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-February/015607.html" ref_id="CESA-2009:0256-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0352" ref_id="CVE-2009-0352"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0353" ref_id="CVE-2009-0353"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0354" ref_id="CVE-2009-0354"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0355" ref_id="CVE-2009-0355"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0356" ref_id="CVE-2009-0356"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0357" ref_id="CVE-2009-0357"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0358" ref_id="CVE-2009-0358"/>
        <description>All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.6, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:03">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:17.990-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:55.024-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:47.691-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:140282"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:140433"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:140471"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:139500"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:140424"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:140387"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:140141"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:139526"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:3.0.6-1.el4" test_ref="oval:org.mitre.oval:tst:139758"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:139536"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:139672"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:140453"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29044" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0849 -- ipsec-tools security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>ipsec-tools</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0849.html" ref_id="RHSA-2008:0849"/>
        <reference source="CESA-2008:0849" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-August/015207.html" ref_id="CESA-2008:0849-CentOS 3"/>
        <reference source="CESA-2008:0849" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-August/015215.html" ref_id="CESA-2008:0849-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3651" ref_id="CVE-2008-3651"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3652" ref_id="CVE-2008-3652"/>
        <description>An updated ipsec-tools package that fixes two security issues is now
available for Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:27.667-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:54.760-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:47.437-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="ipsec-tools is earlier than 0:0.2.5-0.7.rhel3.5" test_ref="oval:org.mitre.oval:tst:138990"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="ipsec-tools is earlier than 0:0.3.3-7.el4_7" test_ref="oval:org.mitre.oval:tst:139264"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="ipsec-tools is earlier than 0:0.6.5-9.el5_2.3" test_ref="oval:org.mitre.oval:tst:139200"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29041" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1463 -- newt security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>newt</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1463.html" ref_id="RHSA-2009:1463"/>
        <reference source="CESA-2009:1463" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-September/016171.html" ref_id="CESA-2009:1463-CentOS 3"/>
        <reference source="CESA-2009:1463" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-October/016256.html" ref_id="CESA-2009:1463-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2905" ref_id="CVE-2009-2905"/>
        <description>Updated newt packages that fix one security issue are now available for Red
Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Newt is a programming library for color text mode, widget-based user
interfaces. Newt can be used to add stacked windows, entry widgets,
checkboxes, radio buttons, labels, plain text fields, scrollbars, and so
on, to text mode user interfaces.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:41">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:06.377-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:54.547-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:47.214-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="newt-devel is earlier than 0:0.52.2-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:139979"/>
            <criterion comment="newt is earlier than 0:0.52.2-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:140776"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="newt is earlier than 0:0.51.5-2.el3" test_ref="oval:org.mitre.oval:tst:140745"/>
            <criterion comment="newt-devel is earlier than 0:0.51.5-2.el3" test_ref="oval:org.mitre.oval:tst:140202"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="newt is earlier than 0:0.51.6-10.el4_8.1" test_ref="oval:org.mitre.oval:tst:139993"/>
            <criterion comment="newt-devel is earlier than 0:0.51.6-10.el4_8.1" test_ref="oval:org.mitre.oval:tst:140602"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29039" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0893 -- bzip2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 2</platform>
          <product>bzip2</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0893.html" ref_id="RHSA-2008:0893"/>
        <reference source="CESA-2008:0893" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-September/015250.html" ref_id="CESA-2008:0893-CentOS 3"/>
        <reference source="CESA-2008:0893" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-September/015252.html" ref_id="CESA-2008:0893-CentOS 5"/>
        <reference source="CESA-2008:0893" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-September/015254.html" ref_id="CESA-2008:0893-CentOS 2"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1372" ref_id="CVE-2008-1372"/>
        <description>Updated bzip2 packages that fix a security issue are now available for Red
Hat Enterprise Linux 2.1, 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Bzip2 is a freely available, high-quality data compressor. It provides both
stand-alone compression and decompression utilities, as well as a shared
library for use with other programs.
A buffer over-read flaw was discovered in the bzip2 decompression routine.
This issue could cause an application linked against the libbz2 library to
crash when decompressing malformed archives. (CVE-2008-1372)
Users of bzip2 should upgrade to these updated packages, which contain a
backported patch to resolve this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:11.537-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:54.329-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:46.963-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bzip2-devel is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:139229"/>
            <criterion comment="bzip2 is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:139072"/>
            <criterion comment="bzip2-libs is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:139145"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bzip2 is earlier than 0:1.0.2-12.EL3" test_ref="oval:org.mitre.oval:tst:139137"/>
            <criterion comment="bzip2-devel is earlier than 0:1.0.2-12.EL3" test_ref="oval:org.mitre.oval:tst:139209"/>
            <criterion comment="bzip2-libs is earlier than 0:1.0.2-12.EL3" test_ref="oval:org.mitre.oval:tst:138972"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bzip2 is earlier than 0:1.0.2-14.el4_7" test_ref="oval:org.mitre.oval:tst:139138"/>
            <criterion comment="bzip2-devel is earlier than 0:1.0.2-14.el4_7" test_ref="oval:org.mitre.oval:tst:139247"/>
            <criterion comment="bzip2-libs is earlier than 0:1.0.2-14.el4_7" test_ref="oval:org.mitre.oval:tst:139210"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29038" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0583 -- openldap security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>openldap</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0583.html" ref_id="RHSA-2008:0583"/>
        <reference source="CESA-2008:0583" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-July/015100.html" ref_id="CESA-2008:0583-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2952" ref_id="CVE-2008-2952"/>
        <description>Updated openldap packages that fix a security issue are now available for
Red Hat Enterprise Linux 4 and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
OpenLDAP is an open source suite of Lightweight Directory Access Protocol
(LDAP) applications and development tools. LDAP is a set of protocols for
accessing directory services.
A denial of service flaw was found in the way the OpenLDAP slapd daemon
processed certain network messages. An unauthenticated remote attacker
could send a specially crafted request that would crash the slapd daemon.
(CVE-2008-2952)
Users of openldap should upgrade to these updated packages, which contain a
backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:31">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:33.048-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:54.112-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:46.690-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openldap-devel is earlier than 0:2.3.27-8.el5_2.4" test_ref="oval:org.mitre.oval:tst:139451"/>
            <criterion comment="openldap-servers is earlier than 0:2.3.27-8.el5_2.4" test_ref="oval:org.mitre.oval:tst:139310"/>
            <criterion comment="openldap-servers-sql is earlier than 0:2.3.27-8.el5_2.4" test_ref="oval:org.mitre.oval:tst:138727"/>
            <criterion comment="compat-openldap is earlier than 0:2.3.27_2.2.29-8.el5_2.4" test_ref="oval:org.mitre.oval:tst:139341"/>
            <criterion comment="openldap is earlier than 0:2.3.27-8.el5_2.4" test_ref="oval:org.mitre.oval:tst:139240"/>
            <criterion comment="openldap-clients is earlier than 0:2.3.27-8.el5_2.4" test_ref="oval:org.mitre.oval:tst:139465"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="compat-openldap is earlier than 0:2.1.30-8.el4_6.5" test_ref="oval:org.mitre.oval:tst:139352"/>
            <criterion comment="openldap is earlier than 0:2.2.13-8.el4_6.5" test_ref="oval:org.mitre.oval:tst:139467"/>
            <criterion comment="openldap-clients is earlier than 0:2.2.13-8.el4_6.5" test_ref="oval:org.mitre.oval:tst:139420"/>
            <criterion comment="openldap-devel is earlier than 0:2.2.13-8.el4_6.5" test_ref="oval:org.mitre.oval:tst:139460"/>
            <criterion comment="openldap-servers is earlier than 0:2.2.13-8.el4_6.5" test_ref="oval:org.mitre.oval:tst:139416"/>
            <criterion comment="openldap-servers-sql is earlier than 0:2.2.13-8.el4_6.5" test_ref="oval:org.mitre.oval:tst:139262"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29030" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0884 -- libxml2 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0884.html" ref_id="RHSA-2008:0884"/>
        <reference source="CESA-2008:0884" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-September/015234.html" ref_id="CESA-2008:0884-CentOS 3"/>
        <reference source="CESA-2008:0884" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-September/015248.html" ref_id="CESA-2008:0884-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3529" ref_id="CVE-2008-3529"/>
        <description>Updated libxml2 packages that fix a security issue are now available for
Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The libxml2 packages provide a library that allows you to manipulate XML
files. It includes support to read, modify, and write XML and HTML files.
A heap-based buffer overflow flaw was found in the way libxml2 handled long
XML entity names. If an application linked against libxml2 processed
untrusted malformed XML content, it could cause the application to crash
or, possibly, execute arbitrary code. (CVE-2008-3529)
All users of libxml2 are advised to upgrade to these updated packages,
which contain a backported patch to resolve this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:12.861-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:53.747-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:46.439-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.6" test_ref="oval:org.mitre.oval:tst:139011"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.2.6" test_ref="oval:org.mitre.oval:tst:138993"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.2.6" test_ref="oval:org.mitre.oval:tst:139100"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.5.10-13" test_ref="oval:org.mitre.oval:tst:139060"/>
            <criterion comment="libxml2-devel is earlier than 0:2.5.10-13" test_ref="oval:org.mitre.oval:tst:139221"/>
            <criterion comment="libxml2-python is earlier than 0:2.5.10-13" test_ref="oval:org.mitre.oval:tst:139131"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.6.16-12.5" test_ref="oval:org.mitre.oval:tst:138431"/>
            <criterion comment="libxml2-devel is earlier than 0:2.6.16-12.5" test_ref="oval:org.mitre.oval:tst:139174"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.16-12.5" test_ref="oval:org.mitre.oval:tst:139099"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29029" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0649 -- libxslt security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>libxslt</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0649.html" ref_id="RHSA-2008:0649"/>
        <reference source="CESA-2008:0649" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-July/015177.html" ref_id="CESA-2008:0649-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2935" ref_id="CVE-2008-2935"/>
        <description>Updated libxslt packages that fix a security issue are now available for
Red Hat Enterprise Linux 4 and Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
libxslt is a library for transforming XML files into other XML files using
the standard XSLT stylesheet transformation mechanism.
A heap buffer overflow flaw was discovered in the RC4 libxslt library
extension. An attacker could create a malicious XSL file that would cause a
crash, or, possibly, execute arbitrary code with the privileges of the
application using the libxslt library to perform XSL transformations on
untrusted XSL style sheets. (CVE-2008-2935)
Red Hat would like to thank Chris Evans for reporting this vulnerability.
All libxslt users are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:20.509-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:53.552-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:46.263-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxslt-devel is earlier than 0:1.1.17-2.el5_2.2" test_ref="oval:org.mitre.oval:tst:139176"/>
            <criterion comment="libxslt is earlier than 0:1.1.17-2.el5_2.2" test_ref="oval:org.mitre.oval:tst:139173"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.17-2.el5_2.2" test_ref="oval:org.mitre.oval:tst:139133"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxslt is earlier than 0:1.1.11-1.el4_7.2" test_ref="oval:org.mitre.oval:tst:138709"/>
            <criterion comment="libxslt-devel is earlier than 0:1.1.11-1.el4_7.2" test_ref="oval:org.mitre.oval:tst:138907"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.11-1.el4_7.2" test_ref="oval:org.mitre.oval:tst:138938"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29028" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0569 -- firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>devhelp</product>
          <product>firefox</product>
          <product>xulrunner</product>
          <product>yelp</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0569.html" ref_id="RHSA-2008:0569"/>
        <reference source="CESA-2008:0569" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-July/015074.html" ref_id="CESA-2008:0569-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2798" ref_id="CVE-2008-2798"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2799" ref_id="CVE-2008-2799"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2800" ref_id="CVE-2008-2800"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2801" ref_id="CVE-2008-2801"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2802" ref_id="CVE-2008-2802"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2803" ref_id="CVE-2008-2803"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2805" ref_id="CVE-2008-2805"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2807" ref_id="CVE-2008-2807"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2808" ref_id="CVE-2008-2808"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2809" ref_id="CVE-2008-2809"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2810" ref_id="CVE-2008-2810"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2811" ref_id="CVE-2008-2811"/>
        <description>Updated firefox packages that fix several security issues are now available
for Red Hat Enterprise Linux 5.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
Mozilla Firefox is an open source Web browser.
Multiple flaws were found in the processing of malformed JavaScript
content. A web page containing such malicious content could cause Firefox
to crash or, potentially, execute arbitrary code as the user running
Firefox. (CVE-2008-2801, CVE-2008-2802, CVE-2008-2803)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:23.121-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:53.401-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:46.095-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:139300"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:138773"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:139358"/>
            <criterion comment="devhelp is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:139385"/>
            <criterion comment="xulrunner is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:139443"/>
            <criterion comment="yelp is earlier than 0:2.16.0-19.el5" test_ref="oval:org.mitre.oval:tst:139472"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:3.0-2.el5" test_ref="oval:org.mitre.oval:tst:139166"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:3.0-2.el5.centos" test_ref="oval:org.mitre.oval:tst:139446"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29022" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1116 -- cyrus-imapd security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>cyrus-imapd</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1116.html" ref_id="RHSA-2009:1116"/>
        <reference source="CESA-2009:1116" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-June/015978.html" ref_id="CESA-2009:1116-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0688" ref_id="CVE-2009-0688"/>
        <description>Updated cyrus-imapd packages that fix a security issue are now available
for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The cyrus-imapd packages contain a high-performance mail server with IMAP,
POP3, NNTP, and SIEVE support.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:16.577-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:52.394-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:45.131-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cyrus-imapd is earlier than 0:2.3.7-2.el5_3.2" test_ref="oval:org.mitre.oval:tst:141048"/>
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.7-2.el5_3.2" test_ref="oval:org.mitre.oval:tst:140157"/>
            <criterion comment="cyrus-imapd-perl is earlier than 0:2.3.7-2.el5_3.2" test_ref="oval:org.mitre.oval:tst:141094"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.7-2.el5_3.2" test_ref="oval:org.mitre.oval:tst:140638"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cyrus-imapd is earlier than 0:2.2.12-10.el4_8.1" test_ref="oval:org.mitre.oval:tst:140841"/>
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.2.12-10.el4_8.1" test_ref="oval:org.mitre.oval:tst:141061"/>
            <criterion comment="cyrus-imapd-murder is earlier than 0:2.2.12-10.el4_8.1" test_ref="oval:org.mitre.oval:tst:140528"/>
            <criterion comment="cyrus-imapd-nntp is earlier than 0:2.2.12-10.el4_8.1" test_ref="oval:org.mitre.oval:tst:141039"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.2.12-10.el4_8.1" test_ref="oval:org.mitre.oval:tst:140102"/>
            <criterion comment="perl-Cyrus is earlier than 0:2.2.12-10.el4_8.1" test_ref="oval:org.mitre.oval:tst:140932"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29020" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0982 -- gnutls security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0982.html" ref_id="RHSA-2008:0982"/>
        <reference source="CESA-2008:0982" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-November/015392.html" ref_id="CESA-2008:0982-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4989" ref_id="CVE-2008-4989"/>
        <description>Updated gnutls packages that fix a security issue are now available for Red
Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS). 
Martin von Gagern discovered a flaw in the way GnuTLS verified certificate
chains provided by a server. A malicious server could use this flaw to
spoof its identity by tricking client applications using the GnuTLS library
to trust invalid certificates. (CVE-2008-4989)
Users of GnuTLS are advised to upgrade to these updated packages, which
contain a backported patch that corrects this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:01.420-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:52.060-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:44.748-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gnutls-devel is earlier than 0:1.4.1-3.el5_2.1" test_ref="oval:org.mitre.oval:tst:140653"/>
          <criterion comment="gnutls is earlier than 0:1.4.1-3.el5_2.1" test_ref="oval:org.mitre.oval:tst:140747"/>
          <criterion comment="gnutls-utils is earlier than 0:1.4.1-3.el5_2.1" test_ref="oval:org.mitre.oval:tst:140326"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29012" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0890 -- wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0890.html" ref_id="RHSA-2008:0890"/>
        <reference source="CESA-2008:0890" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-October/015281.html" ref_id="CESA-2008:0890-CentOS 3"/>
        <reference source="CESA-2008:0890" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-October/015290.html" ref_id="CESA-2008:0890-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1070" ref_id="CVE-2008-1070"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1071" ref_id="CVE-2008-1071"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1072" ref_id="CVE-2008-1072"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1561" ref_id="CVE-2008-1561"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1562" ref_id="CVE-2008-1562"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1563" ref_id="CVE-2008-1563"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3137" ref_id="CVE-2008-3137"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3138" ref_id="CVE-2008-3138"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3141" ref_id="CVE-2008-3141"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3145" ref_id="CVE-2008-3145"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3146" ref_id="CVE-2008-3146"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3932" ref_id="CVE-2008-3932"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3933" ref_id="CVE-2008-3933"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3934" ref_id="CVE-2008-3934"/>
        <description>Updated wireshark packages that fix several security issues are now
available for Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.
Multiple buffer overflow flaws were found in Wireshark. If Wireshark read
a malformed packet off a network, it could crash or, possibly, execute
arbitrary code as the user running Wireshark. (CVE-2008-3146)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:34.159-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:50.274-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:43.041-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:138182"/>
            <criterion comment="wireshark is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:138714"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="wireshark is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:138870"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:139073"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="wireshark is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:138974"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:138902"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29008" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0879 -- firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>devhelp</product>
          <product>nss</product>
          <product>xulrunner</product>
          <product>yelp</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0879.html" ref_id="RHSA-2008:0879"/>
        <reference source="CESA-2008:0879" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-September/015271.html" ref_id="CESA-2008:0879-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3837" ref_id="CVE-2008-3837"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4058" ref_id="CVE-2008-4058"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4060" ref_id="CVE-2008-4060"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4061" ref_id="CVE-2008-4061"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4062" ref_id="CVE-2008-4062"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4063" ref_id="CVE-2008-4063"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4064" ref_id="CVE-2008-4064"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4065" ref_id="CVE-2008-4065"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4067" ref_id="CVE-2008-4067"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4068" ref_id="CVE-2008-4068"/>
        <description>All firefox users should upgrade to this updated package, which contains
backported patches that correct these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:26.294-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:49.926-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:42.630-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:139242"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:139160"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:138911"/>
            <criterion comment="devhelp is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:139097"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:139171"/>
            <criterion comment="yelp is earlier than 0:2.16.0-21.el5" test_ref="oval:org.mitre.oval:tst:139045"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:138903"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:139109"/>
            <criterion comment="firefox is earlier than 0:3.0.2-3.el5" test_ref="oval:org.mitre.oval:tst:139273"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:139177"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:138708"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="firefox is earlier than 0:3.0.2-3.el4" test_ref="oval:org.mitre.oval:tst:139018"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:3.0.2-3.el5.centos" test_ref="oval:org.mitre.oval:tst:139178"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-1.el5.centos.1" test_ref="oval:org.mitre.oval:tst:139127"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-1.el5.centos.1" test_ref="oval:org.mitre.oval:tst:139092"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-1.el5.centos.1" test_ref="oval:org.mitre.oval:tst:138700"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-1.el5.centos.1" test_ref="oval:org.mitre.oval:tst:139250"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28987" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0020 -- bind security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 2</platform>
          <platform>CentOS Linux 3</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0020.html" ref_id="RHSA-2009:0020"/>
        <reference source="CESA-2009:0020" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-January/015538.html" ref_id="CESA-2009:0020-CentOS 5"/>
        <reference source="CESA-2009:0020" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-February/015575.html" ref_id="CESA-2009:0020-CentOS 2"/>
        <reference source="CESA-2009:0020" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-February/015582.html" ref_id="CESA-2009:0020-CentOS 3"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0025" ref_id="CVE-2009-0025"/>
        <description>Updated Bind packages to correct a security issue are now available for Red
Hat Enterprise Linux 2.1, 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols.
A flaw was discovered in the way BIND checked the return value of the
OpenSSL DSA_do_verify function. On systems using DNSSEC, a malicious zone
could present a malformed DSA certificate and bypass proper certificate
validation, allowing spoofing attacks. (CVE-2009-0025)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:06.680-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:49.017-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:42.348-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind-chroot is earlier than 30:9.3.4-6.0.3.P1.el5_2" test_ref="oval:org.mitre.oval:tst:140505"/>
            <criterion comment="bind-devel is earlier than 30:9.3.4-6.0.3.P1.el5_2" test_ref="oval:org.mitre.oval:tst:140497"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.4-6.0.3.P1.el5_2" test_ref="oval:org.mitre.oval:tst:140478"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.4-6.0.3.P1.el5_2" test_ref="oval:org.mitre.oval:tst:140317"/>
            <criterion comment="bind is earlier than 30:9.3.4-6.0.3.P1.el5_2" test_ref="oval:org.mitre.oval:tst:140372"/>
            <criterion comment="bind-libs is earlier than 30:9.3.4-6.0.3.P1.el5_2" test_ref="oval:org.mitre.oval:tst:140179"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.4-6.0.3.P1.el5_2" test_ref="oval:org.mitre.oval:tst:140295"/>
            <criterion comment="bind-utils is earlier than 30:9.3.4-6.0.3.P1.el5_2" test_ref="oval:org.mitre.oval:tst:140146"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 30:9.2.4-23.el3" test_ref="oval:org.mitre.oval:tst:140398"/>
            <criterion comment="bind-chroot is earlier than 30:9.2.4-23.el3" test_ref="oval:org.mitre.oval:tst:139550"/>
            <criterion comment="bind-devel is earlier than 30:9.2.4-23.el3" test_ref="oval:org.mitre.oval:tst:140347"/>
            <criterion comment="bind-libs is earlier than 30:9.2.4-23.el3" test_ref="oval:org.mitre.oval:tst:139734"/>
            <criterion comment="bind-utils is earlier than 30:9.2.4-23.el3" test_ref="oval:org.mitre.oval:tst:140333"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 30:9.2.4-30.el4_7.1" test_ref="oval:org.mitre.oval:tst:140531"/>
            <criterion comment="bind-chroot is earlier than 30:9.2.4-30.el4_7.1" test_ref="oval:org.mitre.oval:tst:140523"/>
            <criterion comment="bind-devel is earlier than 30:9.2.4-30.el4_7.1" test_ref="oval:org.mitre.oval:tst:139958"/>
            <criterion comment="bind-libs is earlier than 30:9.2.4-30.el4_7.1" test_ref="oval:org.mitre.oval:tst:140518"/>
            <criterion comment="bind-utils is earlier than 30:9.2.4-30.el4_7.1" test_ref="oval:org.mitre.oval:tst:140465"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28983" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0612 -- kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0612.html" ref_id="RHSA-2008:0612"/>
        <reference source="CESA-2008:0612" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-August/015181.html" ref_id="CESA-2008:0612-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1294" ref_id="CVE-2008-1294"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2136" ref_id="CVE-2008-2136"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2812" ref_id="CVE-2008-2812"/>
        <description>Updated kernel packages that fix various security issues and several bugs
are now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The kernel packages contain the Linux kernel, the core of any Linux
operating system.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:51.152-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:48.758-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:41.999-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:139046"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:139234"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:139238"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:139294"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:139308"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:138980"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:139284"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:139313"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:139197"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:138332"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28980" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0561 -- ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0561.html" ref_id="RHSA-2008:0561"/>
        <reference source="CESA-2008:0561" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-July/015115.html" ref_id="CESA-2008:0561-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2376" ref_id="CVE-2008-2376"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2662" ref_id="CVE-2008-2662"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2663" ref_id="CVE-2008-2663"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2664" ref_id="CVE-2008-2664"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2725" ref_id="CVE-2008-2725"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2726" ref_id="CVE-2008-2726"/>
        <description>Updated ruby packages that fix several security issues are now available
for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Ruby is an interpreted scripting language for quick and easy
object-oriented programming.
Multiple integer overflows leading to a heap overflow were discovered in
the array- and string-handling code used by Ruby. An attacker could use
these flaws to crash a Ruby application or, possibly, execute arbitrary
code with the privileges of the Ruby application using untrusted inputs in
array or string operations. (CVE-2008-2376, CVE-2008-2662, CVE-2008-2663,
CVE-2008-2725, CVE-2008-2726)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:30">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:09.550-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:48.314-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:41.299-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:138737"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:139026"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:138834"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:139292"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:139055"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:139140"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:139214"/>
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:139261"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:139269"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:138487"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:139447"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:138908"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:138893"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:139374"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:138779"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:139228"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28978" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0341 -- curl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 2</platform>
          <product>curl</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0341.html" ref_id="RHSA-2009:0341"/>
        <reference source="CESA-2009:0341" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-March/015686.html" ref_id="CESA-2009:0341-CentOS 3"/>
        <reference source="CESA-2009:0341" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-March/015698.html" ref_id="CESA-2009:0341-CentOS 2"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0037" ref_id="CVE-2009-0037"/>
        <description>Updated curl packages that fix a security issue are now available for Red
Hat Enterprise Linux 2.1, 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and Dict
servers, using any of the supported protocols. cURL is designed to work
without user interaction or any kind of interactivity.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:54">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:03.592-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:48.152-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:40.871-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="curl-devel is earlier than 0:7.15.5-2.1.el5_3.4" test_ref="oval:org.mitre.oval:tst:140331"/>
            <criterion comment="curl is earlier than 0:7.15.5-2.1.el5_3.4" test_ref="oval:org.mitre.oval:tst:140464"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="curl is earlier than 0:7.10.6-9.rhel3" test_ref="oval:org.mitre.oval:tst:140137"/>
            <criterion comment="curl-devel is earlier than 0:7.10.6-9.rhel3" test_ref="oval:org.mitre.oval:tst:140258"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="curl is earlier than 0:7.12.1-11.1.el4_7.1" test_ref="oval:org.mitre.oval:tst:140380"/>
            <criterion comment="curl-devel is earlier than 0:7.12.1-11.1.el4_7.1" test_ref="oval:org.mitre.oval:tst:140277"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28976" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:1016 -- enscript security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>enscript</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1016.html" ref_id="RHSA-2008:1016"/>
        <reference source="CESA-2008:1016" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-December/015491.html" ref_id="CESA-2008:1016-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3863" ref_id="CVE-2008-3863"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4306" ref_id="CVE-2008-4306"/>
        <description>An updated enscript packages that fixes several security issues is now
available for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
GNU enscript converts ASCII files to PostScript(R) language files and
spools the generated output to a specified printer or saves it to a file.
Enscript can be extended to handle different output media and includes
options for customizing printouts.
Two buffer overflow flaws were found in GNU enscript. An attacker could
craft an ASCII file in such a way that it could execute arbitrary commands
if the file was opened with enscript with the special escapes option (-e
or --escapes) enabled. (CVE-2008-3863, CVE-2008-4306)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:28.161-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:47.751-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:40.430-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="enscript is earlier than 0:1.6.4-4.1.1.el5_2" test_ref="oval:org.mitre.oval:tst:140625"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28973" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0847 -- libtiff security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0847.html" ref_id="RHSA-2008:0847"/>
        <reference source="CESA-2008:0847" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-October/015287.html" ref_id="CESA-2008:0847-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2327" ref_id="CVE-2008-2327"/>
        <description>Updated libtiff packages that fix a security issue and a bug are now
available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.
Multiple uses of uninitialized values were discovered in libtiff's
Lempel-Ziv-Welch (LZW) compression algorithm decoder. An attacker could
create a carefully crafted LZW-encoded TIFF file that would cause an
application linked with libtiff to crash or, possibly, execute arbitrary
code. (CVE-2008-2327)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:16.668-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:47.561-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:40.239-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libtiff-devel is earlier than 0:3.8.2-7.el5_2.2" test_ref="oval:org.mitre.oval:tst:139087"/>
          <criterion comment="libtiff is earlier than 0:3.8.2-7.el5_2.2" test_ref="oval:org.mitre.oval:tst:139213"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28966" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0264 -- kernel security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0264.html" ref_id="RHSA-2009:0264"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4933" ref_id="CVE-2008-4933"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4934" ref_id="CVE-2008-4934"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5025" ref_id="CVE-2008-5025"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5713" ref_id="CVE-2008-5713"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0031" ref_id="CVE-2009-0031"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0065" ref_id="CVE-2009-0065"/>
        <description>Updated kernel packages that resolve several security issues are now
available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The kernel packages contain the Linux kernel, the core of any Linux
operating system.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:25.184-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:47.089-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:39.775-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:139986"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:140305"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:140231"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:140450"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:140184"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:139808"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:140303"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:140373"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:140364"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:140275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28965" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1122 -- icu security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>icu</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1122.html" ref_id="RHSA-2009:1122"/>
        <reference source="CESA-2009:1122" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-June/016003.html" ref_id="CESA-2009:1122-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0153" ref_id="CVE-2009-0153"/>
        <description>Updated icu packages that fix a security issue are now available for Red
Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The International Components for Unicode (ICU) library provides robust and
full-featured Unicode services.
A flaw was found in the way ICU processed certain, invalid byte sequences
during Unicode conversion. If an application used ICU to decode malformed,
multibyte character data, it may have been possible to bypass certain
content protection mechanisms, or display information in a manner
misleading to the user. (CVE-2009-0153)
All users of icu should upgrade to these updated packages, which contain
backported patches to resolve this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:38.782-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:46.911-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:39.581-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libicu-devel is earlier than 0:3.6-5.11.4" test_ref="oval:org.mitre.oval:tst:141064"/>
          <criterion comment="icu is earlier than 0:3.6-5.11.4" test_ref="oval:org.mitre.oval:tst:141055"/>
          <criterion comment="libicu is earlier than 0:3.6-5.11.4" test_ref="oval:org.mitre.oval:tst:141062"/>
          <criterion comment="libicu-doc is earlier than 0:3.6-5.11.4" test_ref="oval:org.mitre.oval:tst:140904"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28964" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0965 -- lynx security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 2</platform>
          <product>lynx</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0965.html" ref_id="RHSA-2008:0965"/>
        <reference source="CESA-2008:0965" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-October/015350.html" ref_id="CESA-2008:0965-CentOS 5"/>
        <reference source="CESA-2008:0965" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-October/015352.html" ref_id="CESA-2008:0965-CentOS 3"/>
        <reference source="CESA-2008:0965" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-October/015360.html" ref_id="CESA-2008:0965-CentOS 2"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7234" ref_id="CVE-2006-7234"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4690" ref_id="CVE-2008-4690"/>
        <description>An updated lynx package that corrects two security issues is now available
for Red Hat Enterprise Linux 2.1, 3, 4, and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
Lynx is a text-based Web browser.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:23.343-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:46.575-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:39.286-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="lynx is earlier than 0:2.8.5-11.3" test_ref="oval:org.mitre.oval:tst:140604"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="lynx is earlier than 0:2.8.5-18.2.el4_7.1" test_ref="oval:org.mitre.oval:tst:140386"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="lynx is earlier than 0:2.8.5-28.1.el5_2.1" test_ref="oval:org.mitre.oval:tst:140753"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28958" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1206 -- libxml and libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>libxml</product>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1206.html" ref_id="RHSA-2009:1206"/>
        <reference source="CESA-2009:1206" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-August/016068.html" ref_id="CESA-2009:1206-CentOS 3"/>
        <reference source="CESA-2009:1206" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-August/016074.html" ref_id="CESA-2009:1206-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2414" ref_id="CVE-2009-2414"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2416" ref_id="CVE-2009-2416"/>
        <description>Updated libxml and libxml2 packages that fix multiple security issues are
now available for Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
libxml is a library for parsing and manipulating XML files. A Document Type
Definition (DTD) defines the legal syntax (and also which elements can be
used) for certain types of files, such as XML files.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:30.987-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:46.346-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:38.955-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.8" test_ref="oval:org.mitre.oval:tst:140698"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.2.8" test_ref="oval:org.mitre.oval:tst:140639"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.2.8" test_ref="oval:org.mitre.oval:tst:140788"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml is earlier than 0:1.8.17-9.3" test_ref="oval:org.mitre.oval:tst:140195"/>
            <criterion comment="libxml-devel is earlier than 1:1.8.17-9.3" test_ref="oval:org.mitre.oval:tst:140644"/>
            <criterion comment="libxml2 is earlier than 0:2.5.10-15" test_ref="oval:org.mitre.oval:tst:140905"/>
            <criterion comment="libxml2-devel is earlier than 0:2.5.10-15" test_ref="oval:org.mitre.oval:tst:140489"/>
            <criterion comment="libxml2-python is earlier than 0:2.5.10-15" test_ref="oval:org.mitre.oval:tst:140887"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.6.16-12.7" test_ref="oval:org.mitre.oval:tst:140897"/>
            <criterion comment="libxml2-devel is earlier than 0:2.6.16-12.7" test_ref="oval:org.mitre.oval:tst:140843"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.16-12.7" test_ref="oval:org.mitre.oval:tst:140882"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28954" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0373 -- systemtap security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>systemtap</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0373.html" ref_id="RHSA-2009:0373"/>
        <reference source="CESA-2009:0373" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-April/015744.html" ref_id="CESA-2009:0373-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0784" ref_id="CVE-2009-0784"/>
        <description>Updated systemtap packages that fix a security issue are now available for
Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
SystemTap is an instrumentation infrastructure for systems running version
2.6 of the Linux kernel. SystemTap scripts can collect system operations
data, greatly simplifying information gathering. Collected data can then
assist in performance measuring, functional testing, and performance and
function problem diagnosis.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:03.208-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:46.157-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:38.746-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="systemtap is earlier than 0:0.6.2-2.el4_7" test_ref="oval:org.mitre.oval:tst:140476"/>
            <criterion comment="systemtap-runtime is earlier than 0:0.6.2-2.el4_7" test_ref="oval:org.mitre.oval:tst:140219"/>
            <criterion comment="systemtap-testsuite is earlier than 0:0.6.2-2.el4_7" test_ref="oval:org.mitre.oval:tst:140457"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="systemtap is earlier than 0:0.7.2-3.el5_3" test_ref="oval:org.mitre.oval:tst:140343"/>
            <criterion comment="systemtap-client is earlier than 0:0.7.2-3.el5_3" test_ref="oval:org.mitre.oval:tst:140449"/>
            <criterion comment="systemtap-runtime is earlier than 0:0.7.2-3.el5_3" test_ref="oval:org.mitre.oval:tst:140113"/>
            <criterion comment="systemtap-server is earlier than 0:0.7.2-3.el5_3" test_ref="oval:org.mitre.oval:tst:140425"/>
            <criterion comment="systemtap-testsuite is earlier than 0:0.7.2-3.el5_3" test_ref="oval:org.mitre.oval:tst:140059"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28953" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1337 -- gfs2-utils security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gfs2-utils</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1337.html" ref_id="RHSA-2009:1337"/>
        <reference source="CESA-2009:1337" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-September/016151.html" ref_id="CESA-2009:1337-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6552" ref_id="CVE-2008-6552"/>
        <description>An updated gfs2-utils package that fixes multiple security issues and
various bugs is now available for Red Hat Enterprise Linux 5.
This update has been rated as having low security impact by the Red Hat
Security Response Team.
The gfs2-utils package provides the user-space tools necessary to mount,
create, maintain, and test GFS2 file systems.
Multiple insecure temporary file use flaws were discovered in GFS2 user
level utilities. A local attacker could use these flaws to overwrite an
arbitrary file writable by a victim running those utilities (typically
root) with the output of the utilities via a symbolic link attack.
(CVE-2008-6552)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:54">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:02.383-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:45.974-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:38.559-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="gfs2-utils is earlier than 0:0.1.62-1.el5" test_ref="oval:org.mitre.oval:tst:140597"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28946" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0476 -- pango security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>pango</product>
          <product>evolution28-pango</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0476.html" ref_id="RHSA-2009:0476"/>
        <reference source="CESA-2009:0476" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-May/015847.html" ref_id="CESA-2009:0476-CentOS 3"/>
        <reference source="CESA-2009:0476" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-May/015853.html" ref_id="CESA-2009:0476-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1194" ref_id="CVE-2009-1194"/>
        <description>Updated pango and evolution28-pango packages that fix an integer overflow
flaw are now available for Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
Pango is a library used for the layout and rendering of internationalized
text.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:01.253-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:45.567-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:38.279-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="pango-devel is earlier than 0:1.14.9-5.el5_3" test_ref="oval:org.mitre.oval:tst:141059"/>
            <criterion comment="pango is earlier than 0:1.14.9-5.el5_3" test_ref="oval:org.mitre.oval:tst:140165"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="pango is earlier than 0:1.2.5-8" test_ref="oval:org.mitre.oval:tst:140809"/>
            <criterion comment="pango-devel is earlier than 0:1.2.5-8" test_ref="oval:org.mitre.oval:tst:140726"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="evolution28-pango is earlier than 0:1.14.9-11.el4_7" test_ref="oval:org.mitre.oval:tst:140524"/>
            <criterion comment="evolution28-pango-devel is earlier than 0:1.14.9-11.el4_7" test_ref="oval:org.mitre.oval:tst:140920"/>
            <criterion comment="pango is earlier than 0:1.6.0-14.4_7" test_ref="oval:org.mitre.oval:tst:140598"/>
            <criterion comment="pango-devel is earlier than 0:1.6.0-14.4_7" test_ref="oval:org.mitre.oval:tst:141163"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="pango is earlier than 0:1.14.9-5.el5.centos" test_ref="oval:org.mitre.oval:tst:141156"/>
            <criterion comment="pango-devel is earlier than 0:1.14.9-5.el5.centos" test_ref="oval:org.mitre.oval:tst:141100"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28941" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1484 -- postgresql security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1484.html" ref_id="RHSA-2009:1484"/>
        <reference source="CESA-2009:1484" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-October/016272.html" ref_id="CESA-2009:1484-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0922" ref_id="CVE-2009-0922"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3230" ref_id="CVE-2009-3230"/>
        <description>Updated postgresql packages that fix two security issues are now available
for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
PostgreSQL is an advanced object-relational database management system
(DBMS).
It was discovered that the upstream patch for CVE-2007-6600 included in the
Red Hat Security Advisory RHSA-2008:0038 did not include protection against
misuse of the RESET ROLE and RESET SESSION AUTHORIZATION commands. An
authenticated user could use this flaw to install malicious code that would
later execute with superuser privileges. (CVE-2009-3230)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:39">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:07.609-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:45.173-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:37.863-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql-devel is earlier than 0:8.1.18-2.el5_4.1" test_ref="oval:org.mitre.oval:tst:140499"/>
            <criterion comment="postgresql-pl is earlier than 0:8.1.18-2.el5_4.1" test_ref="oval:org.mitre.oval:tst:140622"/>
            <criterion comment="postgresql-server is earlier than 0:8.1.18-2.el5_4.1" test_ref="oval:org.mitre.oval:tst:140651"/>
            <criterion comment="postgresql-test is earlier than 0:8.1.18-2.el5_4.1" test_ref="oval:org.mitre.oval:tst:140606"/>
            <criterion comment="postgresql is earlier than 0:8.1.18-2.el5_4.1" test_ref="oval:org.mitre.oval:tst:140485"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.1.18-2.el5_4.1" test_ref="oval:org.mitre.oval:tst:140601"/>
            <criterion comment="postgresql-docs is earlier than 0:8.1.18-2.el5_4.1" test_ref="oval:org.mitre.oval:tst:140554"/>
            <criterion comment="postgresql-libs is earlier than 0:8.1.18-2.el5_4.1" test_ref="oval:org.mitre.oval:tst:140709"/>
            <criterion comment="postgresql-python is earlier than 0:8.1.18-2.el5_4.1" test_ref="oval:org.mitre.oval:tst:140652"/>
            <criterion comment="postgresql-tcl is earlier than 0:8.1.18-2.el5_4.1" test_ref="oval:org.mitre.oval:tst:140005"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql is earlier than 0:7.4.26-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:140239"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.26-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:140789"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.26-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:140115"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.26-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:140713"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.26-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:140805"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.26-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:140611"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.26-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:140742"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.26-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:140770"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.26-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:140740"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.26-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:140506"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.26-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:140775"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28934" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0402 -- openswan security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openswan</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0402.html" ref_id="RHSA-2009:0402"/>
        <reference source="CESA-2009:0402" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-April/015746.html" ref_id="CESA-2009:0402-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4190" ref_id="CVE-2008-4190"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0790" ref_id="CVE-2009-0790"/>
        <description>Updated openswan packages that fix various security issues are now
available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
Openswan is a free implementation of Internet Protocol Security (IPsec)
and Internet Key Exchange (IKE). IPsec uses strong cryptography to provide
both authentication and encryption services. These services allow you to
build secure tunnels through untrusted networks. Everything passing through
the untrusted network is encrypted by the IPsec gateway machine, and
decrypted by the gateway at the other end of the tunnel. The resulting
tunnel is a virtual private network (VPN).</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:14.313-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:44.766-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:37.565-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openswan is earlier than 0:2.6.14-1.el5_3.2" test_ref="oval:org.mitre.oval:tst:140301"/>
          <criterion comment="openswan-doc is earlier than 0:2.6.14-1.el5_3.2" test_ref="oval:org.mitre.oval:tst:139535"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28930" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0892 -- xen security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0892.html" ref_id="RHSA-2008:0892"/>
        <reference source="CESA-2008:0892" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-October/015299.html" ref_id="CESA-2008:0892-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1945" ref_id="CVE-2008-1945"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1952" ref_id="CVE-2008-1952"/>
        <description>Updated xen packages that resolve a couple of security issues and fix a bug
are now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The xen packages contain tools for managing the virtual machine monitor in
Red Hat Virtualization.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:46.778-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:44.558-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:37.300-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="xen-libs is earlier than 0:3.0.3-64.el5_2.3" test_ref="oval:org.mitre.oval:tst:138274"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xen is earlier than 0:3.0.3-64.el5_2.3" test_ref="oval:org.mitre.oval:tst:138896"/>
            <criterion comment="xen-devel is earlier than 0:3.0.3-64.el5_2.3" test_ref="oval:org.mitre.oval:tst:139095"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28929" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1278 -- lftp security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>lftp</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1278.html" ref_id="RHSA-2009:1278"/>
        <reference source="CESA-2009:1278" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-September/016139.html" ref_id="CESA-2009:1278-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2348" ref_id="CVE-2007-2348"/>
        <description>An updated lftp package that fixes one security issue and various bugs is
now available for Red Hat Enterprise Linux 5.
This update has been rated as having low security impact by the Red Hat
Security Response Team.
LFTP is a sophisticated file transfer program for the FTP and HTTP
protocols. Like bash, it has job control and uses the readline library for
input. It has bookmarks, built-in mirroring, and can transfer several files
in parallel. It is designed with reliability in mind.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:31.531-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:44.404-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:37.109-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="lftp is earlier than 0:3.7.11-4.el5" test_ref="oval:org.mitre.oval:tst:140590"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28926" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1471 -- elinks security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>elinks</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1471.html" ref_id="RHSA-2009:1471"/>
        <reference source="CESA-2009:1471" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-October/016224.html" ref_id="CESA-2009:1471-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2027" ref_id="CVE-2007-2027"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7224" ref_id="CVE-2008-7224"/>
        <description>An updated elinks package that fixes two security issues is now available
for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
ELinks is a text-based Web browser. ELinks does not display any images, but
it does support frames, tables, and most other HTML tags.
An off-by-one buffer overflow flaw was discovered in the way ELinks handled
its internal cache of string representations for HTML special entities. A
remote attacker could use this flaw to create a specially-crafted HTML file
that would cause ELinks to crash or, possibly, execute arbitrary code when
rendered. (CVE-2008-7224)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:18.972-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:44.193-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:36.856-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="elinks is earlier than 0:0.9.2-4.el4_8.1" test_ref="oval:org.mitre.oval:tst:140696"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="elinks is earlier than 0:0.11.1-6.el5_4.1" test_ref="oval:org.mitre.oval:tst:140395"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28923" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0046 -- ntp security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>ntp</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0046.html" ref_id="RHSA-2009:0046"/>
        <reference source="CESA-2009:0046" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-April/015755.html" ref_id="CESA-2009:0046-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0021" ref_id="CVE-2009-0021"/>
        <description>Updated ntp packages to correct a security issue are now available for Red
Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The Network Time Protocol (NTP) is used to synchronize a computer's time
with a referenced time source.
A flaw was discovered in the way the ntpd daemon checked the return value
of the OpenSSL EVP_VerifyFinal function. On systems using NTPv4
authentication, this could lead to an incorrect verification of
cryptographic signatures, allowing time-spoofing attacks. (CVE-2009-0021)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:03">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:26.533-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:43.765-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:36.456-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="ntp is earlier than 0:4.2.0.a.20040617-8.el4_7.1" test_ref="oval:org.mitre.oval:tst:139913"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="ntp is earlier than 0:4.2.2p1-9.el5_3.1" test_ref="oval:org.mitre.oval:tst:140492"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="ntp is earlier than 0:4.2.2p1-9.el5.centos.1" test_ref="oval:org.mitre.oval:tst:140430"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28916" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1504 -- poppler security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>poppler</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1504.html" ref_id="RHSA-2009:1504"/>
        <reference source="CESA-2009:1504" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-October/016271.html" ref_id="CESA-2009:1504-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3603" ref_id="CVE-2009-3603"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3608" ref_id="CVE-2009-3608"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3609" ref_id="CVE-2009-3609"/>
        <description>Updated poppler packages that fix multiple security issues and a bug are
now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
Poppler is a Portable Document Format (PDF) rendering library, used by
applications such as Evince.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:26.457-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:43.431-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:35.993-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_4.11" test_ref="oval:org.mitre.oval:tst:140605"/>
          <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_4.11" test_ref="oval:org.mitre.oval:tst:140692"/>
          <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_4.11" test_ref="oval:org.mitre.oval:tst:140687"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28898" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1584 -- java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1584.html" ref_id="RHSA-2009:1584"/>
        <reference source="CESA-2009:1584" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-November/016328.html" ref_id="CESA-2009:1584-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2409" ref_id="CVE-2009-2409"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3728" ref_id="CVE-2009-3728"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3869" ref_id="CVE-2009-3869"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3871" ref_id="CVE-2009-3871"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3873" ref_id="CVE-2009-3873"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3874" ref_id="CVE-2009-3874"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3875" ref_id="CVE-2009-3875"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3876" ref_id="CVE-2009-3876"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3877" ref_id="CVE-2009-3877"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3879" ref_id="CVE-2009-3879"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3880" ref_id="CVE-2009-3880"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3881" ref_id="CVE-2009-3881"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3882" ref_id="CVE-2009-3882"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3883" ref_id="CVE-2009-3883"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3884" ref_id="CVE-2009-3884"/>
        <description>Updated java-1.6.0-openjdk packages that fix several security issues are
now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit. The Java Runtime Environment (JRE)
contains the software and tools that users need to run applications written
using the Java programming language.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:34">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:37:36.379-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:41.297-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:34.836-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:140192"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:139552"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:140136"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:140241"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:140063"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28897" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1502 -- kdegraphics security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kdegraphics</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1502.html" ref_id="RHSA-2009:1502"/>
        <reference source="CESA-2009:1502" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-October/016232.html" ref_id="CESA-2009:1502-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0791" ref_id="CVE-2009-0791"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1188" ref_id="CVE-2009-1188"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3604" ref_id="CVE-2009-3604"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3606" ref_id="CVE-2009-3606"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3608" ref_id="CVE-2009-3608"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3609" ref_id="CVE-2009-3609"/>
        <description>Updated kdegraphics packages that fix multiple security issues are now
available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The kdegraphics packages contain applications for the K Desktop
Environment, including KPDF, a viewer for Portable Document Format (PDF)
files.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:35">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:18.265-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:40.936-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:34.564-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-15.el5_4.2" test_ref="oval:org.mitre.oval:tst:138729"/>
          <criterion comment="kdegraphics is earlier than 7:3.5.4-15.el5_4.2" test_ref="oval:org.mitre.oval:tst:139396"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28896" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0271 -- gstreamer-plugins-good security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>gstreamer-plugins-good</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0271.html" ref_id="RHSA-2009:0271"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0386" ref_id="CVE-2009-0386"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0387" ref_id="CVE-2009-0387"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0397" ref_id="CVE-2009-0397"/>
        <description>Updated gstreamer-plugins-good packages that fix several security issues
are now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
GStreamer is a streaming media framework, based on graphs of filters which
operate on media data. GStreamer Good Plug-ins is a collection of
well-supported, GStreamer plug-ins of good quality released under the LGPL
license.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:00.515-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:40.609-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:34.230-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gstreamer-plugins-good-devel is earlier than 0:0.10.9-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:139677"/>
          <criterion comment="gstreamer-plugins-good is earlier than 0:0.10.9-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:140269"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28894" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1100 -- wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1100.html" ref_id="RHSA-2009:1100"/>
        <reference source="CESA-2009:1100" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-June/015969.html" ref_id="CESA-2009:1100-CentOS 3"/>
        <reference source="CESA-2009:1100" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-June/015987.html" ref_id="CESA-2009:1100-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1210" ref_id="CVE-2009-1210"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1268" ref_id="CVE-2009-1268"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1269" ref_id="CVE-2009-1269"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1829" ref_id="CVE-2009-1829"/>
        <description>Updated wireshark packages that fix several security issues are now
available for Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.
A format string flaw was found in Wireshark. If Wireshark read a malformed
packet off a network or opened a malicious dump file, it could crash or,
possibly, execute arbitrary code as the user running Wireshark. (CVE-2009-1210)
Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2009-1268, CVE-2009-1269, CVE-2009-1829)
Users of wireshark should upgrade to these updated packages, which contain
Wireshark version 1.0.8, and resolve these issues. All running instances of
Wireshark must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:20.199-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:40.165-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:33.796-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="wireshark-gnome is earlier than 0:1.0.8-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:140700"/>
            <criterion comment="wireshark is earlier than 0:1.0.8-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:140402"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="wireshark is earlier than 0:1.0.8-EL3.1" test_ref="oval:org.mitre.oval:tst:141101"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.8-EL3.1" test_ref="oval:org.mitre.oval:tst:140892"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="wireshark is earlier than 0:1.0.8-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:140895"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.8-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:140779"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28888" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1289 -- mysql security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1289.html" ref_id="RHSA-2009:1289"/>
        <reference source="CESA-2009:1289" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-September/016144.html" ref_id="CESA-2009:1289-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2079" ref_id="CVE-2008-2079"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3963" ref_id="CVE-2008-3963"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4456" ref_id="CVE-2008-4456"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2446" ref_id="CVE-2009-2446"/>
        <description>Updated mysql packages that fix various security issues and several bugs
are now available for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:24.650-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:39.697-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:33.419-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mysql-bench is earlier than 0:5.0.77-3.el5" test_ref="oval:org.mitre.oval:tst:140815"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.77-3.el5" test_ref="oval:org.mitre.oval:tst:139909"/>
          <criterion comment="mysql-server is earlier than 0:5.0.77-3.el5" test_ref="oval:org.mitre.oval:tst:140573"/>
          <criterion comment="mysql-test is earlier than 0:5.0.77-3.el5" test_ref="oval:org.mitre.oval:tst:140567"/>
          <criterion comment="mysql is earlier than 0:5.0.77-3.el5" test_ref="oval:org.mitre.oval:tst:140684"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28887" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0486 -- nfs-utils security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>nfs-utils</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0486.html" ref_id="RHSA-2008:0486"/>
        <reference source="CESA-2008:0486" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-July/015179.html" ref_id="CESA-2008:0486-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1376" ref_id="CVE-2008-1376"/>
        <description>An updated nfs-utils package that fixes a security issue is now available
for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The nfs-utils package provides a daemon for the kernel NFS server and
related tools.
A flaw was found in the nfs-utils package build. The nfs-utils package was
missing TCP wrappers support, which could result in an administrator
believing they had access restrictions enabled when they did not.
(CVE-2008-1376)
Users of nfs-utils are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:27.023-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:39.565-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:33.216-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="nfs-utils is earlier than 1:1.0.9-35z.el5_2" test_ref="oval:org.mitre.oval:tst:138566"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28879" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1159 -- libtiff security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1159.html" ref_id="RHSA-2009:1159"/>
        <reference source="CESA-2009:1159" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-July/016036.html" ref_id="CESA-2009:1159-CentOS 3"/>
        <reference source="CESA-2009:1159" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-July/016042.html" ref_id="CESA-2009:1159-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2285" ref_id="CVE-2009-2285"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2347" ref_id="CVE-2009-2347"/>
        <description>Updated libtiff packages that fix several security issues are now available
for Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:36.674-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:39.247-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:32.925-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-7.el5_3.4" test_ref="oval:org.mitre.oval:tst:140723"/>
            <criterion comment="libtiff is earlier than 0:3.8.2-7.el5_3.4" test_ref="oval:org.mitre.oval:tst:141014"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtiff is earlier than 0:3.5.7-33.el3" test_ref="oval:org.mitre.oval:tst:140923"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-33.el3" test_ref="oval:org.mitre.oval:tst:140854"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtiff is earlier than 0:3.6.1-12.el4_8.4" test_ref="oval:org.mitre.oval:tst:140043"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-12.el4_8.4" test_ref="oval:org.mitre.oval:tst:140596"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28869" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0480 -- poppler security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>poppler</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0480.html" ref_id="RHSA-2009:0480"/>
        <reference source="CESA-2009:0480" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-May/015865.html" ref_id="CESA-2009:0480-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0146" ref_id="CVE-2009-0146"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0147" ref_id="CVE-2009-0147"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0166" ref_id="CVE-2009-0166"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0195" ref_id="CVE-2009-0195"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0791" ref_id="CVE-2009-0791"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0799" ref_id="CVE-2009-0799"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0800" ref_id="CVE-2009-0800"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1179" ref_id="CVE-2009-1179"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1180" ref_id="CVE-2009-1180"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1181" ref_id="CVE-2009-1181"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1182" ref_id="CVE-2009-1182"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1183" ref_id="CVE-2009-1183"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1187" ref_id="CVE-2009-1187"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1188" ref_id="CVE-2009-1188"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3604" ref_id="CVE-2009-3604"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3606" ref_id="CVE-2009-3606"/>
        <description>Updated poppler packages that fix multiple security issues are now
available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
Poppler is a Portable Document Format (PDF) rendering library, used by
applications such as Evince.
Multiple integer overflow flaws were found in poppler. An attacker could
create a malicious PDF file that would cause applications that use poppler
(such as Evince) to crash or, potentially, execute arbitrary code when
opened. (CVE-2009-0147, CVE-2009-1179, CVE-2009-1187, CVE-2009-1188)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:25.263-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:38.422-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:32.443-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:140752"/>
          <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:140821"/>
          <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:140829"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28862" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1670 -- kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1670.html" ref_id="RHSA-2009:1670"/>
        <reference source="CESA-2009:1670" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-December/016374.html" ref_id="CESA-2009:1670-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3612" ref_id="CVE-2009-3612"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3620" ref_id="CVE-2009-3620"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3621" ref_id="CVE-2009-3621"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3726" ref_id="CVE-2009-3726"/>
        <description>Updated kernel packages that fix multiple security issues and several bugs
are now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The kernel packages contain the Linux kernel, the core of any Linux
operating system.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:37:48.785-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:38.044-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:32.027-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:140203"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:139851"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:140207"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:140153"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:139254"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:139555"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:139448"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:140103"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:140216"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:139930"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28850" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0259 -- mod_auth_mysql security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>mod_auth_mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0259.html" ref_id="RHSA-2009:0259"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2384" ref_id="CVE-2008-2384"/>
        <description>An updated mod_auth_mysql package to correct a security issue is now
available for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The mod_auth_mysql package includes an extension module for the Apache HTTP
Server which can be used to implement web user authentication against a
MySQL database.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:00.890-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:37.890-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:31.785-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="mod_auth_mysql is earlier than 1:3.0.0-3.2.el5_3" test_ref="oval:org.mitre.oval:tst:140388"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28842" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0815 -- yum-rhn-plugin security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>yum-rhn-plugin</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0815.html" ref_id="RHSA-2008:0815"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3270" ref_id="CVE-2008-3270"/>
        <description>Updated yum-rhn-plugin packages that fix a security issue are now available
for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The yum-rhn-plugin provides support for yum to securely access a Red Hat
Network (RHN) server for software updates.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:30.511-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:37.201-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:31.565-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="yum-rhn-plugin is earlier than 0:0.5.3-12.el5_2.9" test_ref="oval:org.mitre.oval:tst:139143"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28838" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0474 -- acpid security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>acpid</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0474.html" ref_id="RHSA-2009:0474"/>
        <reference source="CESA-2009:0474" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-May/015846.html" ref_id="CESA-2009:0474-CentOS 3"/>
        <reference source="CESA-2009:0474" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-May/015873.html" ref_id="CESA-2009:0474-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0798" ref_id="CVE-2009-0798"/>
        <description>An updated acpid package that fixes one security issue is now available
for Red Hat Enterprise Linux 2.1, 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
acpid is a daemon that dispatches ACPI (Advanced Configuration and Power
Interface) events to user-space programs.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:13.448-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:36.969-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:31.320-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="acpid is earlier than 0:1.0.2-4" test_ref="oval:org.mitre.oval:tst:139783"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="acpid is earlier than 0:1.0.3-2.el4_7.1" test_ref="oval:org.mitre.oval:tst:140189"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="acpid is earlier than 0:1.0.4-7.el5_3.1" test_ref="oval:org.mitre.oval:tst:139311"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28800" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1075 -- httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1075.html" ref_id="RHSA-2009:1075"/>
        <reference source="CESA-2009:1075" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-May/015953.html" ref_id="CESA-2009:1075-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1678" ref_id="CVE-2008-1678"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1195" ref_id="CVE-2009-1195"/>
        <description>Updated httpd packages that fix two security issues are now available for
Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The Apache HTTP Server is a popular and freely-available Web server.
A flaw was found in the handling of compression structures between mod_ssl
and OpenSSL. If too many connections were opened in a short period of time,
all system memory and swap space would be consumed by httpd, negatively
impacting other processes, or causing a system crash. (CVE-2008-1678)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:33.240-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:36.011-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:30.664-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd-devel is earlier than 0:2.2.3-22.el5_3.1" test_ref="oval:org.mitre.oval:tst:140704"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-22.el5_3.1" test_ref="oval:org.mitre.oval:tst:141096"/>
            <criterion comment="httpd is earlier than 0:2.2.3-22.el5_3.1" test_ref="oval:org.mitre.oval:tst:140508"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-22.el5_3.1" test_ref="oval:org.mitre.oval:tst:140501"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd is earlier than 0:2.2.3-22.el5.centos.1" test_ref="oval:org.mitre.oval:tst:140715"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-22.el5.centos.1" test_ref="oval:org.mitre.oval:tst:140112"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-22.el5.centos.1" test_ref="oval:org.mitre.oval:tst:140942"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-22.el5.centos.1" test_ref="oval:org.mitre.oval:tst:140150"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28793" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0326 -- kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0326.html" ref_id="RHSA-2009:0326"/>
        <reference source="CESA-2009:0326" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-April/015712.html" ref_id="CESA-2009:0326-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3528" ref_id="CVE-2008-3528"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5700" ref_id="CVE-2008-5700"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0028" ref_id="CVE-2009-0028"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0269" ref_id="CVE-2009-0269"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0322" ref_id="CVE-2009-0322"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0675" ref_id="CVE-2009-0675"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0676" ref_id="CVE-2009-0676"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0778" ref_id="CVE-2009-0778"/>
        <description>Updated kernel packages that fix several security issues and several bugs
are now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The kernel packages contain the Linux kernel, the core of any Linux
operating system.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:41">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:27.062-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:34.922-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:29.269-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:140369"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:140191"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:140225"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:140405"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:139624"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:139799"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:139475"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:140174"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:140126"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:140344"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-debug-debuginfo is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:140391"/>
            <criterion comment="kernel-debuginfo is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:140244"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:140371"/>
            <criterion comment="kernel-PAE-debuginfo is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:140290"/>
            <criterion comment="kernel-xen-debuginfo is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:140325"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28787" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0533 -- bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 2</platform>
          <platform>CentOS Linux 3</platform>
          <product>bind</product>
          <product>selinux-policy-targeted</product>
          <product>selinux-policy</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0533.html" ref_id="RHSA-2008:0533"/>
        <reference source="CESA-2008:0533" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-July/015077.html" ref_id="CESA-2008:0533-CentOS 5"/>
        <reference source="CESA-2008:0533" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-July/015082.html" ref_id="CESA-2008:0533-CentOS 2"/>
        <reference source="CESA-2008:0533" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-July/015083.html" ref_id="CESA-2008:0533-CentOS 3"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447" ref_id="CVE-2008-1447"/>
        <description>Updated bind packages that help mitigate DNS spoofing attacks are now
available. 
This update has been rated as having important security impact by the Red
Hat Security Response Team.
We have updated the Enterprise Linux 5 packages in this advisory. The
default and sample caching-nameserver configuration files have been updated
so that they do not specify a fixed query-source port.  Administrators
wishing to take advantage of randomized UDP source ports should check their
configuration file to ensure they have not specified fixed query-source ports.
ISC BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:30">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:22.160-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:33.638-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:27.987-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind-chroot is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:139168"/>
            <criterion comment="bind-devel is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:139484"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:139306"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:139251"/>
            <criterion comment="selinux-policy-devel is earlier than 0:2.4.6-137.1.el5_2" test_ref="oval:org.mitre.oval:tst:139116"/>
            <criterion comment="bind is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:139260"/>
            <criterion comment="bind-libs is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:139035"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:139192"/>
            <criterion comment="bind-utils is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:138935"/>
            <criterion comment="selinux-policy is earlier than 0:2.4.6-137.1.el5_2" test_ref="oval:org.mitre.oval:tst:139208"/>
            <criterion comment="selinux-policy-mls is earlier than 0:2.4.6-137.1.el5_2" test_ref="oval:org.mitre.oval:tst:139195"/>
            <criterion comment="selinux-policy-strict is earlier than 0:2.4.6-137.1.el5_2" test_ref="oval:org.mitre.oval:tst:139356"/>
            <criterion comment="selinux-policy-targeted is earlier than 0:2.4.6-137.1.el5_2" test_ref="oval:org.mitre.oval:tst:139104"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 30:9.2.4-22.el3" test_ref="oval:org.mitre.oval:tst:139096"/>
            <criterion comment="bind-chroot is earlier than 30:9.2.4-22.el3" test_ref="oval:org.mitre.oval:tst:139330"/>
            <criterion comment="bind-devel is earlier than 30:9.2.4-22.el3" test_ref="oval:org.mitre.oval:tst:139418"/>
            <criterion comment="bind-libs is earlier than 30:9.2.4-22.el3" test_ref="oval:org.mitre.oval:tst:138746"/>
            <criterion comment="bind-utils is earlier than 30:9.2.4-22.el3" test_ref="oval:org.mitre.oval:tst:139469"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 30:9.2.4-28.0.1.el4" test_ref="oval:org.mitre.oval:tst:139070"/>
            <criterion comment="bind-chroot is earlier than 30:9.2.4-28.0.1.el4" test_ref="oval:org.mitre.oval:tst:139224"/>
            <criterion comment="bind-devel is earlier than 30:9.2.4-28.0.1.el4" test_ref="oval:org.mitre.oval:tst:139239"/>
            <criterion comment="bind-libs is earlier than 30:9.2.4-28.0.1.el4" test_ref="oval:org.mitre.oval:tst:139207"/>
            <criterion comment="bind-utils is earlier than 30:9.2.4-28.0.1.el4" test_ref="oval:org.mitre.oval:tst:138788"/>
            <criterion comment="selinux-policy-targeted is earlier than 0:1.17.30-2.150.el4" test_ref="oval:org.mitre.oval:tst:138871"/>
            <criterion comment="selinux-policy-targeted-sources is earlier than 0:1.17.30-2.150.el4" test_ref="oval:org.mitre.oval:tst:139293"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 30:9.3.4-6.0.1.P1.el5_2" test_ref="oval:org.mitre.oval:tst:139381"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.4-6.0.1.P1.el5_2" test_ref="oval:org.mitre.oval:tst:139183"/>
            <criterion comment="bind-devel is earlier than 30:9.3.4-6.0.1.P1.el5_2" test_ref="oval:org.mitre.oval:tst:139485"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.4-6.0.1.P1.el5_2" test_ref="oval:org.mitre.oval:tst:139033"/>
            <criterion comment="bind-libs is earlier than 30:9.3.4-6.0.1.P1.el5_2" test_ref="oval:org.mitre.oval:tst:139404"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.4-6.0.1.P1.el5_2" test_ref="oval:org.mitre.oval:tst:139387"/>
            <criterion comment="bind-utils is earlier than 30:9.3.4-6.0.1.P1.el5_2" test_ref="oval:org.mitre.oval:tst:139175"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.4-6.0.1.P1.el5_2" test_ref="oval:org.mitre.oval:tst:139216"/>
            <criterion comment="selinux-policy is earlier than 0:2.4.6-137.1.el5" test_ref="oval:org.mitre.oval:tst:139328"/>
            <criterion comment="selinux-policy-devel is earlier than 0:2.4.6-137.1.el5" test_ref="oval:org.mitre.oval:tst:139291"/>
            <criterion comment="selinux-policy-mls is earlier than 0:2.4.6-137.1.el5" test_ref="oval:org.mitre.oval:tst:139477"/>
            <criterion comment="selinux-policy-strict is earlier than 0:2.4.6-137.1.el5" test_ref="oval:org.mitre.oval:tst:139421"/>
            <criterion comment="selinux-policy-targeted is earlier than 0:2.4.6-137.1.el5" test_ref="oval:org.mitre.oval:tst:139480"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28776" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0003 -- xen security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0003.html" ref_id="RHSA-2009:0003"/>
        <reference source="CESA-2009:0003" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-January/015535.html" ref_id="CESA-2009:0003-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4405" ref_id="CVE-2008-4405"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4993" ref_id="CVE-2008-4993"/>
        <description>Updated xen packages that resolve several security issues and a bug are now
available for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The xen packages contain the Xen tools and management daemons needed to
manage virtual machines running on Red Hat Enterprise Linux.
Xen was found to allow unprivileged DomU domains to overwrite xenstore
values which should only be changeable by the privileged Dom0 domain. An
attacker controlling a DomU domain could, potentially, use this flaw to
kill arbitrary processes in Dom0 or trick a Dom0 user into accessing the
text console of a different domain running on the same host. This update
makes certain parts of the xenstore tree read-only to the unprivileged DomU
domains. (CVE-2008-4405)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:19.407-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:33.413-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:27.682-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="xen-libs is earlier than 0:3.0.3-64.el5_2.9" test_ref="oval:org.mitre.oval:tst:139584"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xen is earlier than 0:3.0.3-64.el5_2.9" test_ref="oval:org.mitre.oval:tst:140114"/>
            <criterion comment="xen-devel is earlier than 0:3.0.3-64.el5_2.9" test_ref="oval:org.mitre.oval:tst:140456"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28765" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1453 -- pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1453.html" ref_id="RHSA-2009:1453"/>
        <reference source="CESA-2009:1453" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-October/016269.html" ref_id="CESA-2009:1453-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2703" ref_id="CVE-2009-2703"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3026" ref_id="CVE-2009-3026"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3083" ref_id="CVE-2009-3083"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3085" ref_id="CVE-2009-3085"/>
        <description>Updated pidgin packages that fix several security issues are now available
for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously. Info/Query
(IQ) is an Extensible Messaging and Presence Protocol (XMPP) specific
request-response mechanism.
A NULL pointer dereference flaw was found in the way the Pidgin XMPP
protocol plug-in processes IQ error responses when trying to fetch a custom
smiley. A remote client could send a specially-crafted IQ error response
that would crash Pidgin. (CVE-2009-3085)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:17.707-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:32.491-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:26.814-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="finch-devel is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:139415"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:138489"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:139110"/>
            <criterion comment="finch is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:139305"/>
            <criterion comment="libpurple is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:138800"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:139135"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:139433"/>
            <criterion comment="pidgin is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:139103"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:139471"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="finch is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:139357"/>
            <criterion comment="finch-devel is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:139252"/>
            <criterion comment="libpurple is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:139268"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:139235"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:139249"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:139152"/>
            <criterion comment="pidgin is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:139150"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:138652"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:139479"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28758" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1459 -- cyrus-imapd security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>cyrus-imapd</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1459.html" ref_id="RHSA-2009:1459"/>
        <reference source="CESA-2009:1459" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-October/016220.html" ref_id="CESA-2009:1459-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2632" ref_id="CVE-2009-2632"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3235" ref_id="CVE-2009-3235"/>
        <description>Updated cyrus-imapd packages that fix several security issues are now
available for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The cyrus-imapd packages contain a high-performance mail server with IMAP,
POP3, NNTP, and Sieve support.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:42">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:26.969-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:32.043-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:26.392-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cyrus-imapd is earlier than 0:2.3.7-7.el5_4.3" test_ref="oval:org.mitre.oval:tst:140496"/>
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.7-7.el5_4.3" test_ref="oval:org.mitre.oval:tst:140569"/>
            <criterion comment="cyrus-imapd-perl is earlier than 0:2.3.7-7.el5_4.3" test_ref="oval:org.mitre.oval:tst:140796"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.7-7.el5_4.3" test_ref="oval:org.mitre.oval:tst:140401"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cyrus-imapd is earlier than 0:2.2.12-10.el4_8.4" test_ref="oval:org.mitre.oval:tst:140530"/>
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.2.12-10.el4_8.4" test_ref="oval:org.mitre.oval:tst:140678"/>
            <criterion comment="cyrus-imapd-murder is earlier than 0:2.2.12-10.el4_8.4" test_ref="oval:org.mitre.oval:tst:140803"/>
            <criterion comment="cyrus-imapd-nntp is earlier than 0:2.2.12-10.el4_8.4" test_ref="oval:org.mitre.oval:tst:140716"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.2.12-10.el4_8.4" test_ref="oval:org.mitre.oval:tst:140575"/>
            <criterion comment="perl-Cyrus is earlier than 0:2.2.12-10.el4_8.4" test_ref="oval:org.mitre.oval:tst:140077"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28749" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1335 -- openssl security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1335.html" ref_id="RHSA-2009:1335"/>
        <reference source="CESA-2009:1335" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-September/016149.html" ref_id="CESA-2009:1335-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7250" ref_id="CVE-2006-7250"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0590" ref_id="CVE-2009-0590"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1377" ref_id="CVE-2009-1377"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1378" ref_id="CVE-2009-1378"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1379" ref_id="CVE-2009-1379"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1386" ref_id="CVE-2009-1386"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1387" ref_id="CVE-2009-1387"/>
        <description>Updated openssl packages that fix several security issues, various bugs,
and add enhancements are now available for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a full-strength
general purpose cryptography library. Datagram TLS (DTLS) is a protocol
based on TLS that is capable of securing datagram transport (for example,
UDP).</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:09.167-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:31.597-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:25.869-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-12.el5" test_ref="oval:org.mitre.oval:tst:140853"/>
          <criterion comment="openssl is earlier than 0:0.9.8e-12.el5" test_ref="oval:org.mitre.oval:tst:140488"/>
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-12.el5" test_ref="oval:org.mitre.oval:tst:140632"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28741" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0354 -- evolution-data-server security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>evolution28-evolution-data-server</product>
          <product>evolution-data-server</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0354.html" ref_id="RHSA-2009:0354"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0547" ref_id="CVE-2009-0547"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0582" ref_id="CVE-2009-0582"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0587" ref_id="CVE-2009-0587"/>
        <description>Updated evolution-data-server and evolution28-evolution-data-server
packages that fix multiple security issues are now available for Red Hat
Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Evolution Data Server provides a unified back-end for applications which
interact with contacts, task, and calendar information. Evolution Data
Server was originally developed as a back-end for Evolution, but is now
used by multiple other applications.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:30.232-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:31.070-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:25.590-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="evolution-data-server-devel is earlier than 0:1.12.3-10.el5_3.3" test_ref="oval:org.mitre.oval:tst:140255"/>
            <criterion comment="evolution-data-server is earlier than 0:1.12.3-10.el5_3.3" test_ref="oval:org.mitre.oval:tst:139962"/>
            <criterion comment="evolution-data-server-doc is earlier than 0:1.12.3-10.el5_3.3" test_ref="oval:org.mitre.oval:tst:140218"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="evolution28-evolution-data-server is earlier than 0:1.8.0-37.el4_7.2" test_ref="oval:org.mitre.oval:tst:140413"/>
            <criterion comment="evolution28-evolution-data-server-devel is earlier than 0:1.8.0-37.el4_7.2" test_ref="oval:org.mitre.oval:tst:140474"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28736" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0449 -- firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0449.html" ref_id="RHSA-2009:0449"/>
        <reference source="CESA-2009:0449" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-April/015831.html" ref_id="CESA-2009:0449-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1313" ref_id="CVE-2009-1313"/>
        <description>Updated firefox packages that fix one security issue are now available for
Red Hat Enterprise Linux 4 and 5.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.
A flaw was found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-1313)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:29.676-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:30.561-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:25.341-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.10-1.el5" test_ref="oval:org.mitre.oval:tst:140160"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.10-1.el5" test_ref="oval:org.mitre.oval:tst:139657"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.10-1.el5" test_ref="oval:org.mitre.oval:tst:140196"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:3.0.10-1.el5" test_ref="oval:org.mitre.oval:tst:140199"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="firefox is earlier than 0:3.0.10-1.el4" test_ref="oval:org.mitre.oval:tst:140280"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:3.0.10-1.el5.centos" test_ref="oval:org.mitre.oval:tst:140291"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28716" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0616 -- thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0616.html" ref_id="RHSA-2008:0616"/>
        <reference source="CESA-2008:0616" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-July/015159.html" ref_id="CESA-2008:0616-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2785" ref_id="CVE-2008-2785"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2798" ref_id="CVE-2008-2798"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2799" ref_id="CVE-2008-2799"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2800" ref_id="CVE-2008-2800"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2801" ref_id="CVE-2008-2801"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2802" ref_id="CVE-2008-2802"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2803" ref_id="CVE-2008-2803"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2805" ref_id="CVE-2008-2805"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2807" ref_id="CVE-2008-2807"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2808" ref_id="CVE-2008-2808"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2809" ref_id="CVE-2008-2809"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2810" ref_id="CVE-2008-2810"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2811" ref_id="CVE-2008-2811"/>
        <description>Updated thunderbird packages that fix a security issue are now available
for Red Hat Enterprise Linux 4 and Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Mozilla Thunderbird is a standalone mail and newsgroup client.
Multiple flaws were found in the processing of malformed JavaScript
content. An HTML mail containing such malicious content could cause
Thunderbird to crash or, potentially, execute arbitrary code as the user
running Thunderbird. (CVE-2008-2801, CVE-2008-2802, CVE-2008-2803)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:55:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:34:30.543-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:28.949-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:24.491-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="thunderbird is earlier than 0:1.5.0.12-14.el4" test_ref="oval:org.mitre.oval:tst:139651"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.16-1.el5" test_ref="oval:org.mitre.oval:tst:139795"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28712" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0004 -- openssl security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 2</platform>
          <product>openssl</product>
          <product>openssl095a</product>
          <product>openssl096</product>
          <product>openssl096b</product>
          <product>openssl097a</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0004.html" ref_id="RHSA-2009:0004"/>
        <reference source="CESA-2009:0004" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-January/015522.html" ref_id="CESA-2009:0004-CentOS 3"/>
        <reference source="CESA-2009:0004" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-January/015532.html" ref_id="CESA-2009:0004-CentOS 5"/>
        <reference source="CESA-2009:0004" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-February/015574.html" ref_id="CESA-2009:0004-CentOS 2"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5077" ref_id="CVE-2008-5077"/>
        <description>Updated OpenSSL packages that correct a security issue are now available
for Red Hat Enterprise Linux 2.1, 3, 4, and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
OpenSSL is a toolkit that implements Secure Sockets Layer (SSL v2/v3) and
Transport Layer Security (TLS v1) protocols as well as a full-strength,
general purpose, cryptography library.
The Google security team discovered a flaw in the way OpenSSL checked the
verification of certificates. An attacker in control of a malicious server,
or able to effect a man in the middle attack, could present a malformed
SSL/TLS signature from a certificate chain to a vulnerable client and
bypass validation. (CVE-2008-5077)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:39:54.345-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:28.674-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:24.077-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl-devel is earlier than 0:0.9.8b-10.el5_2.1" test_ref="oval:org.mitre.oval:tst:140259"/>
            <criterion comment="openssl is earlier than 0:0.9.8b-10.el5_2.1" test_ref="oval:org.mitre.oval:tst:140341"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8b-10.el5_2.1" test_ref="oval:org.mitre.oval:tst:140419"/>
            <criterion comment="openssl097a is earlier than 0:0.9.7a-9.el5_2.1" test_ref="oval:org.mitre.oval:tst:139591"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:0.9.7a-33.25" test_ref="oval:org.mitre.oval:tst:140394"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-33.25" test_ref="oval:org.mitre.oval:tst:140156"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-33.25" test_ref="oval:org.mitre.oval:tst:140483"/>
            <criterion comment="openssl096b is earlier than 0:0.9.6b-16.49" test_ref="oval:org.mitre.oval:tst:140346"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:0.9.7a-43.17.el4_7.2" test_ref="oval:org.mitre.oval:tst:140500"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-43.17.el4_7.2" test_ref="oval:org.mitre.oval:tst:140514"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-43.17.el4_7.2" test_ref="oval:org.mitre.oval:tst:140254"/>
            <criterion comment="openssl096b is earlier than 0:0.9.6b-22.46.el4_7" test_ref="oval:org.mitre.oval:tst:140549"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28703" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0427 -- udev security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>udev</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0427.html" ref_id="RHSA-2009:0427"/>
        <reference source="CESA-2009:0427" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-April/015797.html" ref_id="CESA-2009:0427-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1185" ref_id="CVE-2009-1185"/>
        <description>Updated udev packages that fix one security issue are now available for Red
Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
udev provides a user-space API and implements a dynamic device directory,
providing only the devices present on the system. udev replaces devfs in
order to provide greater hot plug functionality. Netlink is a datagram
oriented service, used to transfer information between kernel modules and
user-space processes.
It was discovered that udev did not properly check the origin of Netlink
messages. A local attacker could use this flaw to gain root privileges via
a crafted Netlink message sent to udev, causing it to create a
world-writable block device file for an existing system block device (for
example, the root file system). (CVE-2009-1185)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:31">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:39:58.072-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:28.477-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:23.796-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libvolume_id-devel is earlier than 0:095-14.20.el5_3" test_ref="oval:org.mitre.oval:tst:140250"/>
          <criterion comment="libvolume_id is earlier than 0:095-14.20.el5_3" test_ref="oval:org.mitre.oval:tst:139965"/>
          <criterion comment="udev is earlier than 0:095-14.20.el5_3" test_ref="oval:org.mitre.oval:tst:139917"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28693" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0908 -- thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0908.html" ref_id="RHSA-2008:0908"/>
        <reference source="CESA-2008:0908" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-October/015292.html" ref_id="CESA-2008:0908-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0016" ref_id="CVE-2008-0016"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3835" ref_id="CVE-2008-3835"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4058" ref_id="CVE-2008-4058"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4059" ref_id="CVE-2008-4059"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4060" ref_id="CVE-2008-4060"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4061" ref_id="CVE-2008-4061"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4062" ref_id="CVE-2008-4062"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4065" ref_id="CVE-2008-4065"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4066" ref_id="CVE-2008-4066"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4067" ref_id="CVE-2008-4067"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4068" ref_id="CVE-2008-4068"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4070" ref_id="CVE-2008-4070"/>
        <description>Updated thunderbird packages that fix several security issues are now
available for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Mozilla Thunderbird is a standalone mail and newsgroup client.
Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2008-0016, CVE-2008-4058, CVE-2008-4059, CVE-2008-4060,
CVE-2008-4061, CVE-2008-4062)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:34:39.399-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:27.367-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:22.628-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="thunderbird is earlier than 0:1.5.0.12-16.el4" test_ref="oval:org.mitre.oval:tst:139881"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.17-1.el5" test_ref="oval:org.mitre.oval:tst:139840"/>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.17-1.el5.centos" test_ref="oval:org.mitre.oval:tst:139384"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28686" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0981 -- ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0981.html" ref_id="RHSA-2008:0981"/>
        <reference source="CESA-2008:0981" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-December/015473.html" ref_id="CESA-2008:0981-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4310" ref_id="CVE-2008-4310"/>
        <description>Updated ruby packages that fix a security issue are now available for Red
Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.
Vincent Danen reported, that Red Hat Security Advisory RHSA-2008:0897
did not properly address a denial of service flaw in the WEBrick (Ruby
HTTP server toolkit), known as CVE-2008-3656. This flaw allowed a
remote attacker to send a specially-crafted HTTP request to a WEBrick
server that would cause the server to use excessive CPU time. This
update properly addresses this flaw. (CVE-2008-4310)
All Ruby users should upgrade to these updated packages, which contain a
correct patch that resolves this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:02.666-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:27.087-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:22.349-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.6" test_ref="oval:org.mitre.oval:tst:140116"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.6" test_ref="oval:org.mitre.oval:tst:139699"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.6" test_ref="oval:org.mitre.oval:tst:140555"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.6" test_ref="oval:org.mitre.oval:tst:140562"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.6" test_ref="oval:org.mitre.oval:tst:140310"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.6" test_ref="oval:org.mitre.oval:tst:140613"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.6" test_ref="oval:org.mitre.oval:tst:140100"/>
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.6" test_ref="oval:org.mitre.oval:tst:140384"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.6" test_ref="oval:org.mitre.oval:tst:140276"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_7.2" test_ref="oval:org.mitre.oval:tst:140360"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_7.2" test_ref="oval:org.mitre.oval:tst:140548"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_7.2" test_ref="oval:org.mitre.oval:tst:140614"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_7.2" test_ref="oval:org.mitre.oval:tst:139730"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_7.2" test_ref="oval:org.mitre.oval:tst:140669"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_7.2" test_ref="oval:org.mitre.oval:tst:140543"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_7.2" test_ref="oval:org.mitre.oval:tst:140680"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28661" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1974 -- rpm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <product>rpm</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1974.html" ref_id="RHSA-2014:1974"/>
        <reference source="CESA-2014:1974-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020818.html" ref_id="CESA-2014:1974-CentOS 6"/>
        <reference source="CESA-2014:1974-CentOS 5" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020819.html" ref_id="CESA-2014:1974-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6435" ref_id="CVE-2013-6435"/>
        <description>The RPM Package Manager (RPM) is a powerful command line driven package
management system capable of installing, uninstalling, verifying, querying,
and updating software packages. Each software package consists of an
archive of files along with information about the package such as its
version, description, and other information.

It was found that RPM wrote file contents to the target installation
directory under a temporary name, and verified its cryptographic signature
only after the temporary file has been written completely. Under certain
conditions, the system interprets the unverified temporary file contents
and extracts commands from it. This could allow an attacker to modify
signed RPM files in such a way that they would execute code chosen by the
attacker during package installation. (CVE-2013-6435)

This issue was discovered by Florian Weimer of Red Hat Product Security.

All rpm users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. All running applications
linked against the RPM library must be restarted for this update to take
effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-30T11:33:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:14:21.363-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:36.271-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:32.228-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="rpm-apidocs is earlier than 0:4.4.2.3-36.el5_11" test_ref="oval:org.mitre.oval:tst:136922"/>
            <criterion comment="rpm-build is earlier than 0:4.4.2.3-36.el5_11" test_ref="oval:org.mitre.oval:tst:136747"/>
            <criterion comment="rpm-devel is earlier than 0:4.4.2.3-36.el5_11" test_ref="oval:org.mitre.oval:tst:137062"/>
            <criterion comment="popt is earlier than 0:1.10.2.3-36.el5_11" test_ref="oval:org.mitre.oval:tst:136793"/>
            <criterion comment="rpm is earlier than 0:4.4.2.3-36.el5_11" test_ref="oval:org.mitre.oval:tst:137165"/>
            <criterion comment="rpm-libs is earlier than 0:4.4.2.3-36.el5_11" test_ref="oval:org.mitre.oval:tst:136878"/>
            <criterion comment="rpm-python is earlier than 0:4.4.2.3-36.el5_11" test_ref="oval:org.mitre.oval:tst:137235"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="rpm-debuginfo is earlier than 0:4.4.2.3-36.el5_11" test_ref="oval:org.mitre.oval:tst:137172"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="rpm is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137024"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:136811"/>
            <criterion comment="rpm-build is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137066"/>
            <criterion comment="rpm-cron is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137047"/>
            <criterion comment="rpm-devel is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137248"/>
            <criterion comment="rpm-libs is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:136765"/>
            <criterion comment="rpm-python is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137213"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="rpm-debuginfo is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137203"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28652" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1982 -- xorg-x11-server security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1982.html" ref_id="RHSA-2014:1982"/>
        <reference source="CESA-2014:1982" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020825.html" ref_id="CESA-2014:1982"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8091" ref_id="CVE-2014-8091"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8092" ref_id="CVE-2014-8092"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8093" ref_id="CVE-2014-8093"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8095" ref_id="CVE-2014-8095"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8096" ref_id="CVE-2014-8096"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8097" ref_id="CVE-2014-8097"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8098" ref_id="CVE-2014-8098"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8099" ref_id="CVE-2014-8099"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8100" ref_id="CVE-2014-8100"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8101" ref_id="CVE-2014-8101"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8102" ref_id="CVE-2014-8102"/>
        <description>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

Multiple integer overflow flaws and out-of-bounds write flaws were found in
the way the X.Org server calculated memory requirements for certain X11
core protocol and GLX extension requests. A malicious, authenticated client
could use either of these flaws to crash the X.Org server or, potentially,
execute arbitrary code with root privileges. (CVE-2014-8092, CVE-2014-8093,
CVE-2014-8098)

It was found that the X.Org server did not properly handle SUN-DES-1
(Secure RPC) authentication credentials. A malicious, unauthenticated
client could use this flaw to crash the X.Org server by submitting a
specially crafted authentication request. (CVE-2014-8091)

Multiple out-of-bounds access flaws were found in the way the X.Org server
calculated memory requirements for certain requests. A malicious,
authenticated client could use either of these flaws to crash the X.Org
server, or leak memory contents to the client. (CVE-2014-8097)

Multiple out-of-bounds access flaws were found in the way the X.Org server
calculated memory requirements for certain requests. A malicious,
authenticated client could use either of these flaws to crash the X.Org
server. (CVE-2014-8095, CVE-2014-8096, CVE-2014-8099, CVE-2014-8100,
CVE-2014-8101, CVE-2014-8102)

All xorg-x11-server users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-30T11:32:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:14:19.988-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:35.882-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:31.960-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server-debuginfo is earlier than 0:1.1.1-48.107.el5_11" test_ref="oval:org.mitre.oval:tst:136985"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.107.el5_11" test_ref="oval:org.mitre.oval:tst:136732"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.107.el5_11" test_ref="oval:org.mitre.oval:tst:137131"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.107.el5_11" test_ref="oval:org.mitre.oval:tst:136937"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.107.el5_11" test_ref="oval:org.mitre.oval:tst:136903"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.107.el5_11" test_ref="oval:org.mitre.oval:tst:137140"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.107.el5_11" test_ref="oval:org.mitre.oval:tst:136872"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.107.el5_11" test_ref="oval:org.mitre.oval:tst:137218"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.107.el5.centos" test_ref="oval:org.mitre.oval:tst:137184"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.107.el5.centos" test_ref="oval:org.mitre.oval:tst:137142"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.107.el5.centos" test_ref="oval:org.mitre.oval:tst:137110"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.107.el5.centos" test_ref="oval:org.mitre.oval:tst:136986"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.107.el5.centos" test_ref="oval:org.mitre.oval:tst:136828"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.107.el5.centos" test_ref="oval:org.mitre.oval:tst:137238"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.107.el5.centos" test_ref="oval:org.mitre.oval:tst:137219"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28629" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1179 -- bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1179.html" ref_id="RHSA-2009:1179"/>
        <reference source="CESA-2009:1179" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-July/016052.html" ref_id="CESA-2009:1179-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0696" ref_id="CVE-2009-0696"/>
        <description>Updated bind packages that fix a security issue are now available for Red
Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
[Updated 29th July 2009]
The packages in this erratum have been updated to also correct this issue
in the bind-sdb package.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:37.655-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:24.234-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:21.548-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind-chroot is earlier than 30:9.3.4-10.P1.el5_3.3" test_ref="oval:org.mitre.oval:tst:140566"/>
            <criterion comment="bind-devel is earlier than 30:9.3.4-10.P1.el5_3.3" test_ref="oval:org.mitre.oval:tst:140714"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.4-10.P1.el5_3.3" test_ref="oval:org.mitre.oval:tst:140950"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.4-10.P1.el5_3.3" test_ref="oval:org.mitre.oval:tst:140830"/>
            <criterion comment="bind is earlier than 30:9.3.4-10.P1.el5_3.3" test_ref="oval:org.mitre.oval:tst:140820"/>
            <criterion comment="bind-libs is earlier than 30:9.3.4-10.P1.el5_3.3" test_ref="oval:org.mitre.oval:tst:140469"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.4-10.P1.el5_3.3" test_ref="oval:org.mitre.oval:tst:140860"/>
            <criterion comment="bind-utils is earlier than 30:9.3.4-10.P1.el5_3.3" test_ref="oval:org.mitre.oval:tst:140656"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 30:9.3.4-10.P1.el5_3.2" test_ref="oval:org.mitre.oval:tst:140631"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.4-10.P1.el5_3.2" test_ref="oval:org.mitre.oval:tst:140827"/>
            <criterion comment="bind-devel is earlier than 30:9.3.4-10.P1.el5_3.2" test_ref="oval:org.mitre.oval:tst:140561"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.4-10.P1.el5_3.2" test_ref="oval:org.mitre.oval:tst:140832"/>
            <criterion comment="bind-libs is earlier than 30:9.3.4-10.P1.el5_3.2" test_ref="oval:org.mitre.oval:tst:140976"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.4-10.P1.el5_3.2" test_ref="oval:org.mitre.oval:tst:140535"/>
            <criterion comment="bind-utils is earlier than 30:9.3.4-10.P1.el5_3.2" test_ref="oval:org.mitre.oval:tst:140316"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.4-10.P1.el5_3.2" test_ref="oval:org.mitre.oval:tst:140293"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28627" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1222 -- kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1222.html" ref_id="RHSA-2009:1222"/>
        <reference source="CESA-2009:1222" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-August/016109.html" ref_id="CESA-2009:1222-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2692" ref_id="CVE-2009-2692"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2698" ref_id="CVE-2009-2698"/>
        <description>Updated kernel packages that fix two security issues and a bug are now
available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The kernel packages contain the Linux kernel, the core of any Linux
operating system.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:23.770-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:23.929-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:21.221-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:140778"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:140907"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:140877"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:140695"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:140777"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:140623"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:140503"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:140767"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:140910"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:140406"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28617" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1106 -- kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1106.html" ref_id="RHSA-2009:1106"/>
        <reference source="CESA-2009:1106" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-June/015975.html" ref_id="CESA-2009:1106-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1072" ref_id="CVE-2009-1072"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1192" ref_id="CVE-2009-1192"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1439" ref_id="CVE-2009-1439"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1630" ref_id="CVE-2009-1630"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1633" ref_id="CVE-2009-1633"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1758" ref_id="CVE-2009-1758"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3238" ref_id="CVE-2009-3238"/>
        <description>Updated kernel packages that fix several security issues and several bugs
are now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The kernel packages contain the Linux kernel, the core of any Linux
operating system.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:28.275-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:23.287-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:20.628-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:140621"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:140807"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:141016"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:141049"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:140840"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:140839"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:140721"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:140838"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:141083"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:140847"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28592" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0429 -- cups security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0429.html" ref_id="RHSA-2009:0429"/>
        <reference source="CESA-2009:0429" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-April/015794.html" ref_id="CESA-2009:0429-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0146" ref_id="CVE-2009-0146"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0147" ref_id="CVE-2009-0147"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0163" ref_id="CVE-2009-0163"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0166" ref_id="CVE-2009-0166"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0195" ref_id="CVE-2009-0195"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0799" ref_id="CVE-2009-0799"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0800" ref_id="CVE-2009-0800"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1179" ref_id="CVE-2009-1179"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1180" ref_id="CVE-2009-1180"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1181" ref_id="CVE-2009-1181"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1182" ref_id="CVE-2009-1182"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1183" ref_id="CVE-2009-1183"/>
        <description>Updated cups packages that fix multiple security issues are now available
for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:33">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:15.865-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:21.088-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:19.120-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:140168"/>
            <criterion comment="cups is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:140167"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:139317"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:140287"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:140308"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:140309"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:139867"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28588" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1984 -- bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1984.html" ref_id="RHSA-2014:1984"/>
        <reference source="CESA-2014:1984-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020827.html" ref_id="CESA-2014:1984-CentOS 6"/>
        <reference source="CESA-2014:1984-CentOS 7" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020828.html" ref_id="CESA-2014:1984-CentOS 7"/>
        <reference source="CESA-2014:1984-CentOS 5" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020829.html" ref_id="CESA-2014:1984-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8500" ref_id="CVE-2014-8500"/>
        <description>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A denial of service flaw was found in the way BIND followed DNS
delegations. A remote attacker could use a specially crafted zone
containing a large number of referrals which, when looked up and processed,
would cause named to use excessive amounts of memory or crash.
(CVE-2014-8500)

All bind users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-30T11:32:47">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:14:33.156-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:32.517-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:137244 - Updated Linux patches with modified epoch in states." date="2015-02-02T16:00:00.461-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-23T04:01:28.627-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:55.055-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind-chroot is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136991"/>
            <criterion comment="bind-debuginfo is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:137141"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:137013"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:137022"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136320"/>
            <criterion comment="bind is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:137046"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136841"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:137052"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:137085"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:136550"/>
            <criterion comment="bind-chroot is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:136248"/>
            <criterion comment="bind-devel is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:137244"/>
            <criterion comment="bind-libs is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:137092"/>
            <criterion comment="bind-sdb is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:137206"/>
            <criterion comment="bind-utils is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:137146"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="bind-debuginfo is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:137117"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:136944"/>
            <criterion comment="bind-chroot is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:137006"/>
            <criterion comment="bind-devel is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:136436"/>
            <criterion comment="bind-libs is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:137151"/>
            <criterion comment="bind-libs-lite is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:137044"/>
            <criterion comment="bind-license is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:136871"/>
            <criterion comment="bind-lite-devel is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:136695"/>
            <criterion comment="bind-sdb is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:136926"/>
            <criterion comment="bind-sdb-chroot is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:137048"/>
            <criterion comment="bind-utils is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:136778"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criterion comment="bind-debuginfo is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:137177"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28539" version="3" class="patch">
      <metadata>
        <title>RHSA-2015:1002-01 -- Redhat xen</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference source="VENDOR" ref_url="https://www.redhat.com/archives/rhsa-announce/2015-May/msg00013.html" ref_id="RHSA-2015:1002-01"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3456" ref_id="CVE-2015-3456"/>
        <description>The xen packages contain administration tools and the xend service for managing the kernel-xen kernel for virtualization on Red Hat Enterprise Linux. An out-of-bounds memory access flaw was found in the way QEMU"s virtual Floppy Disk Controller  handled FIFO buffer access while processing certain FDC commands. A privileged guest user could use this flaw to crash the guest or, potentially, execute arbitrary code on the host with the privileges of the host"s QEMU process corresponding to the guest.  Red Hat would like to thank Jason Geffner of CrowdStrike for reporting this issue. All xen users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. After installing the updated packages, all running fully-virtualized guests must be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-02T15:20:15">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-03T12:30:17.392-04:00">DRAFT</status_change>
            <status_change date="2015-06-22T04:00:43.387-04:00">INTERIM</status_change>
            <status_change date="2015-07-13T04:00:10.723-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="All dependent packages of xen">
          <criterion comment="xen is earlier than 0:3.0.3-146.el5_11" test_ref="oval:org.mitre.oval:tst:138720"/>
          <criterion comment="xen-debuginfo is earlier than 0:3.0.3-146.el5_11" test_ref="oval:org.mitre.oval:tst:138433"/>
          <criterion comment="xen-libs is earlier than 0:3.0.3-146.el5_11" test_ref="oval:org.mitre.oval:tst:138283"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28514" version="3" class="patch">
      <metadata>
        <title>RHSA-2015:0800 -- openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2015-0800.html" ref_id="RHSA-2015:0800"/>
        <reference source="CESA-2015:0800" ref_url="http://lists.centos.org/pipermail/centos-announce/2015-April/021064.html" ref_id="CESA-2015:0800"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8275" ref_id="CVE-2014-8275"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0204" ref_id="CVE-2015-0204"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0287" ref_id="CVE-2015-0287"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0288" ref_id="CVE-2015-0288"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0289" ref_id="CVE-2015-0289"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0292" ref_id="CVE-2015-0292"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0293" ref_id="CVE-2015-0293"/>
        <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.
It was discovered that OpenSSL would accept ephemeral RSA keys when using
non-export RSA cipher suites. A malicious server could make a TLS/SSL
client using OpenSSL use a weaker key exchange method. (CVE-2015-0204)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:37:24.232-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:18.487-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:18.284-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="openssl-debuginfo is earlier than 0:0.9.8e-33.el5_11" test_ref="oval:org.mitre.oval:tst:140051"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-33.el5_11" test_ref="oval:org.mitre.oval:tst:140187"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-33.el5_11" test_ref="oval:org.mitre.oval:tst:140210"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-33.el5_11" test_ref="oval:org.mitre.oval:tst:139632"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28498" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1985 -- bind97 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1985.html" ref_id="RHSA-2014:1985"/>
        <reference source="CESA-2014:1985" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020826.html" ref_id="CESA-2014:1985"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8500" ref_id="CVE-2014-8500"/>
        <description>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A denial of service flaw was found in the way BIND followed DNS
delegations. A remote attacker could use a specially crafted zone
containing a large number of referrals which, when looked up and processed,
would cause named to use excessive amounts of memory or crash.
(CVE-2014-8500)

All bind97 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-30T11:32:42">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:14:21.764-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:27.771-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:137100 - Updated Linux patches with modified epoch in states." date="2015-02-02T16:00:00.461-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-23T04:01:24.962-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:53.404-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind97 is earlier than 32:9.7.0-21.P2.el5_11.1" test_ref="oval:org.mitre.oval:tst:137080"/>
          <criterion comment="bind97-chroot is earlier than 32:9.7.0-21.P2.el5_11.1" test_ref="oval:org.mitre.oval:tst:136973"/>
          <criterion comment="bind97-debuginfo is earlier than 32:9.7.0-21.P2.el5_11.1" test_ref="oval:org.mitre.oval:tst:136919"/>
          <criterion comment="bind97-devel is earlier than 32:9.7.0-21.P2.el5_11.1" test_ref="oval:org.mitre.oval:tst:137018"/>
          <criterion comment="bind97-libs is earlier than 32:9.7.0-21.P2.el5_11.1" test_ref="oval:org.mitre.oval:tst:137100"/>
          <criterion comment="bind97-utils is earlier than 32:9.7.0-21.P2.el5_11.1" test_ref="oval:org.mitre.oval:tst:136784"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28495" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1036 -- ipsec-tools security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>ipsec-tools</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1036.html" ref_id="RHSA-2009:1036"/>
        <reference source="CESA-2009:1036" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-May/015880.html" ref_id="CESA-2009:1036-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1574" ref_id="CVE-2009-1574"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1632" ref_id="CVE-2009-1632"/>
        <description>An updated ipsec-tools package that fixes multiple security issues is now
available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The ipsec-tools package is used in conjunction with the IPsec functionality
in the Linux kernel and includes racoon, an IKEv1 keying daemon.
A denial of service flaw was found in the ipsec-tools racoon daemon. An
unauthenticated, remote attacker could trigger a NULL pointer dereference
that could cause the racoon daemon to crash. (CVE-2009-1574)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:08.262-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:17.301-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:17.942-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="ipsec-tools is earlier than 0:0.6.5-13.el5_3.1" test_ref="oval:org.mitre.oval:tst:141060"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28460" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:2025 -- ntp security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>ntp</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-2025.html" ref_id="RHSA-2014:2025"/>
        <reference source="CESA-2014:2025" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020851.html" ref_id="CESA-2014:2025"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9293" ref_id="CVE-2014-9293"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9294" ref_id="CVE-2014-9294"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9295" ref_id="CVE-2014-9295"/>
        <description>The Network Time Protocol (NTP) is used to synchronize a computer&amp;#39;s time
with a referenced time source.

Multiple buffer overflow flaws were discovered in ntpd&amp;#39;s crypto_recv(),
ctl_putdata(), and configure() functions. A remote attacker could use
either of these flaws to send a specially crafted request packet that could
crash ntpd or, potentially, execute arbitrary code with the privileges of
the ntp user. Note: the crypto_recv() flaw requires non-default
configurations to be active, while the ctl_putdata() flaw, by default, can
only be exploited via local attackers, and the configure() flaw requires
additional authentication to exploit. (CVE-2014-9295)

It was found that ntpd automatically generated weak keys for its internal
use if no ntpdc request authentication key was specified in the ntp.conf
configuration file. A remote attacker able to match the configured IP
restrictions could guess the generated key, and possibly use it to send
ntpdc query or configuration requests. (CVE-2014-9293)

It was found that ntp-keygen used a weak method for generating MD5 keys.
This could possibly allow an attacker to guess generated MD5 keys that
could then be used to spoof an NTP client or server. Note: it is
recommended to regenerate any MD5 keys that had explicitly been generated
with ntp-keygen; the default installation does not contain such keys).
(CVE-2014-9294)

All ntp users are advised to upgrade to this updated package, which
contains backported patches to resolve these issues. After installing the
update, the ntpd daemon will restart automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-30T11:32:30">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:14:23.177-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:24.391-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:37784 - Updated States &amp; Objects" date="2015-02-02T15:56:00.526-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-23T04:01:21.892-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:52.216-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ntp is earlier than 0:4.2.2p1-18.el5_11" test_ref="oval:org.mitre.oval:tst:136694"/>
            <criterion comment="ntp-debuginfo is earlier than 0:4.2.2p1-18.el5_11" test_ref="oval:org.mitre.oval:tst:137069"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="ntp is earlier than 0:4.2.2p1-18.el5.centos" test_ref="oval:org.mitre.oval:tst:136750"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28459" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1924 -- thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1924.html" ref_id="RHSA-2014:1924"/>
        <reference source="CESA-2014:1924-CentOS 5" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020797.html" ref_id="CESA-2014:1924-CentOS 5"/>
        <reference source="CESA-2014:1924-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020799.html" ref_id="CESA-2014:1924-CentOS 6"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1587" ref_id="CVE-2014-1587"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1590" ref_id="CVE-2014-1590"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1592" ref_id="CVE-2014-1592"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1593" ref_id="CVE-2014-1593"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1594" ref_id="CVE-2014-1594"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1587, CVE-2014-1590, CVE-2014-1592, CVE-2014-1593)

A flaw was found in the Alarm API, which could allow applications to
schedule actions to be run in the future. A malicious web application could
use this flaw to bypass the same-origin policy. (CVE-2014-1594)

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

This update disables SSL 3.0 support by default in Thunderbird. Details on
how to re-enable SSL 3.0 support are available at:
&lt;A HREF="https://access.redhat.com/articles/1284233">https://access.redhat.com/articles/1284233&lt;/A>

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Randell Jesup, Nils Ohlmeier, Jesse
Ruderman, Max Jonas Werner, Joe Vennix, Berend-Jan Wever, Abhishek Arya,
and Boris Zbarsky as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 31.3.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 31.3.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:37:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:35:54.010-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:44.520-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:46.232-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="thunderbird is earlier than 0:31.3.0-1.el5_11" test_ref="oval:org.mitre.oval:tst:136206"/>
            <criterion comment="thunderbird-debuginfo is earlier than 0:31.3.0-1.el5_11" test_ref="oval:org.mitre.oval:tst:136131"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="thunderbird is earlier than 0:31.3.0-1.el6_6" test_ref="oval:org.mitre.oval:tst:136134"/>
            <criterion comment="thunderbird-debuginfo is earlier than 0:31.3.0-1.el6_6" test_ref="oval:org.mitre.oval:tst:135692"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:31.3.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:135513"/>
        </criteria>
        <criteria comment="CentOS Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criterion comment="thunderbird is earlier than 0:31.3.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:135999"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28453" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:2008 -- kernel security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-2008.html" ref_id="RHSA-2014:2008"/>
        <reference source="CESA-2014:2008" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020842.html" ref_id="CESA-2014:2008"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9322" ref_id="CVE-2014-9322"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel handled GS segment register
base switching when recovering from a #SS (stack segment) fault on an
erroneous return to user space. A local, unprivileged user could use this
flaw to escalate their privileges on the system. (CVE-2014-9322, Important)

Red Hat would like to thank Andy Lutomirski for reporting this issue.

All kernel users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. The system must be
rebooted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-30T11:32:34">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:14:28.747-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:23.898-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:21.664-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:137053"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:136351"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:136511"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:136994"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:136459"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:137001"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:136391"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:136736"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:136155"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:136867"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-PAE-debuginfo is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:136182"/>
            <criterion comment="kernel-debug-debuginfo is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:137063"/>
            <criterion comment="kernel-debuginfo is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:137003"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:137152"/>
            <criterion comment="kernel-xen-debuginfo is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:137090"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28421" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:0408 -- krb5 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0408.html" ref_id="RHSA-2009:0408"/>
        <reference source="CESA-2009:0408" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-April/015736.html" ref_id="CESA-2009:0408-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0844" ref_id="CVE-2009-0844"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0845" ref_id="CVE-2009-0845"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0846" ref_id="CVE-2009-0846"/>
        <description>Updated krb5 packages that fix various security issues are now available
for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third party, the Key Distribution Center (KDC). The Generic
Security Service Application Program Interface (GSS-API) definition
provides security services to callers (protocols) in a generic fashion. The
Simple and Protected GSS-API Negotiation (SPNEGO) mechanism is used by
GSS-API peers to choose from a common set of security mechanisms.
An input validation flaw was found in the ASN.1 (Abstract Syntax Notation
One) decoder used by MIT Kerberos. A remote attacker could use this flaw to
crash a network service using the MIT Kerberos library, such as kadmind or
krb5kdc, by causing it to dereference or free an uninitialized pointer.
(CVE-2009-0846)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:40:30.804-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:15.445-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:17.265-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="krb5-devel is earlier than 0:1.6.1-31.el5_3.3" test_ref="oval:org.mitre.oval:tst:140251"/>
          <criterion comment="krb5-server is earlier than 0:1.6.1-31.el5_3.3" test_ref="oval:org.mitre.oval:tst:139823"/>
          <criterion comment="krb5-libs is earlier than 0:1.6.1-31.el5_3.3" test_ref="oval:org.mitre.oval:tst:140208"/>
          <criterion comment="krb5-workstation is earlier than 0:1.6.1-31.el5_3.3" test_ref="oval:org.mitre.oval:tst:140217"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28407" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0648 -- tomcat security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>tomcat5</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0648.html" ref_id="RHSA-2008:0648"/>
        <reference source="CESA-2008:0648" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-August/015217.html" ref_id="CESA-2008:0648-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1232" ref_id="CVE-2008-1232"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1947" ref_id="CVE-2008-1947"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2370" ref_id="CVE-2008-2370"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2938" ref_id="CVE-2008-2938"/>
        <description>Updated tomcat packages that fix several security issues are now available
for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.
A cross-site scripting vulnerability was discovered in the
HttpServletResponse.sendErrormethod. A remote attacker could inject
arbitrary web script or HTML via forged HTTP headers. (CVE-2008-1232)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:28.373-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:14.899-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:16.848-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.7.el5_2.1" test_ref="oval:org.mitre.oval:tst:138959"/>
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.7.el5_2.1" test_ref="oval:org.mitre.oval:tst:139061"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.7.el5_2.1" test_ref="oval:org.mitre.oval:tst:139032"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.7.el5_2.1" test_ref="oval:org.mitre.oval:tst:138953"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.7.el5_2.1" test_ref="oval:org.mitre.oval:tst:139167"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.7.el5_2.1" test_ref="oval:org.mitre.oval:tst:139244"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.7.el5_2.1" test_ref="oval:org.mitre.oval:tst:138719"/>
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.7.el5_2.1" test_ref="oval:org.mitre.oval:tst:139253"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.7.el5_2.1" test_ref="oval:org.mitre.oval:tst:138326"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.7.el5_2.1" test_ref="oval:org.mitre.oval:tst:139134"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.7.el5_2.1" test_ref="oval:org.mitre.oval:tst:139198"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28396" version="3" class="patch">
      <metadata>
        <title>RHSA-2009:1148 -- httpd security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1148.html" ref_id="RHSA-2009:1148"/>
        <reference source="CESA-2009:1148" ref_url="http://lists.centos.org/pipermail/centos-announce/2009-July/016028.html" ref_id="CESA-2009:1148-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1890" ref_id="CVE-2009-1890"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1891" ref_id="CVE-2009-1891"/>
        <description>Updated httpd packages that fix two security issues are now available for
Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
The Apache HTTP Server is a popular Web server.
A denial of service flaw was found in the Apache mod_proxy module when it
was used as a reverse proxy. A remote attacker could use this flaw to force
a proxy process to consume large amounts of CPU time. (CVE-2009-1890)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:53:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T11:17:20.959-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:14.437-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:16.434-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd-devel is earlier than 0:2.2.3-22.el5_3.2" test_ref="oval:org.mitre.oval:tst:140936"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-22.el5_3.2" test_ref="oval:org.mitre.oval:tst:140350"/>
            <criterion comment="httpd is earlier than 0:2.2.3-22.el5_3.2" test_ref="oval:org.mitre.oval:tst:140580"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-22.el5_3.2" test_ref="oval:org.mitre.oval:tst:140927"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd is earlier than 0:2.2.3-22.el5.centos.2" test_ref="oval:org.mitre.oval:tst:140525"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-22.el5.centos.2" test_ref="oval:org.mitre.oval:tst:140763"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-22.el5.centos.2" test_ref="oval:org.mitre.oval:tst:140545"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-22.el5.centos.2" test_ref="oval:org.mitre.oval:tst:141033"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28389" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1859 -- mysql55-mysql security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>mysql55-mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1859.html" ref_id="RHSA-2014:1859"/>
        <reference source="CESA-2014:1859" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-November/020762.html" ref_id="CESA-2014:1859"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5615" ref_id="CVE-2012-5615"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2494" ref_id="CVE-2014-2494"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4207" ref_id="CVE-2014-4207"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4243" ref_id="CVE-2014-4243"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4258" ref_id="CVE-2014-4258"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4260" ref_id="CVE-2014-4260"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4274" ref_id="CVE-2014-4274"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4287" ref_id="CVE-2014-4287"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6463" ref_id="CVE-2014-6463"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6464" ref_id="CVE-2014-6464"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6469" ref_id="CVE-2014-6469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6484" ref_id="CVE-2014-6484"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6505" ref_id="CVE-2014-6505"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6507" ref_id="CVE-2014-6507"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6520" ref_id="CVE-2014-6520"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6530" ref_id="CVE-2014-6530"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6551" ref_id="CVE-2014-6551"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6555" ref_id="CVE-2014-6555"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6559" ref_id="CVE-2014-6559"/>
        <description>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

This update fixes several vulnerabilities in the MySQL database server.
Information about these flaws can be found on the Oracle Critical Patch
Update Advisory page, listed in the References section. (CVE-2014-2494,
CVE-2014-4207, CVE-2014-4243, CVE-2014-4258, CVE-2014-4260, CVE-2014-4287, 
CVE-2014-4274, CVE-2014-6463, CVE-2014-6464, CVE-2014-6469, CVE-2014-6484, 
CVE-2014-6505, CVE-2014-6507, CVE-2014-6520, CVE-2014-6530, CVE-2014-6551, 
CVE-2014-6555, CVE-2014-6559)

These updated packages upgrade MySQL to version 5.5.40. Refer to the MySQL
Release Notes listed in the References section for a complete list of
changes.

All MySQL users should upgrade to these updated packages, which correct
these issues. After installing this update, the MySQL server daemon
(mysqld) will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:37:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:36:01.965-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:38.378-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:40.878-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="mysql55-mysql-debuginfo is earlier than 0:5.5.40-2.el5" test_ref="oval:org.mitre.oval:tst:135921"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="mysql55-mysql-devel is earlier than 0:5.5.40-2.el5" test_ref="oval:org.mitre.oval:tst:136168"/>
            <criterion comment="mysql55-mysql is earlier than 0:5.5.40-2.el5" test_ref="oval:org.mitre.oval:tst:135750"/>
            <criterion comment="mysql55-mysql-bench is earlier than 0:5.5.40-2.el5" test_ref="oval:org.mitre.oval:tst:135584"/>
            <criterion comment="mysql55-mysql-libs is earlier than 0:5.5.40-2.el5" test_ref="oval:org.mitre.oval:tst:136114"/>
            <criterion comment="mysql55-mysql-server is earlier than 0:5.5.40-2.el5" test_ref="oval:org.mitre.oval:tst:136053"/>
            <criterion comment="mysql55-mysql-test is earlier than 0:5.5.40-2.el5" test_ref="oval:org.mitre.oval:tst:136137"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28360" version="3" class="patch">
      <metadata>
        <title>RHSA-2015:0090 -- glibc security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2015-0090.html" ref_id="RHSA-2015:0090"/>
        <reference source="CESA-2015:0090" ref_url="http://lists.centos.org/pipermail/centos-announce/2015-January/020906.html" ref_id="CESA-2015:0090"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0235" ref_id="CVE-2015-0235"/>
        <description>The glibc packages provide the standard C libraries (libc), POSIX thread
libraries (libpthread), standard math libraries (libm), and the Name
Server Caching Daemon (nscd) used by multiple programs on the system.
Without these libraries, the Linux system cannot function correctly.

A heap-based buffer overflow was found in glibc&amp;#39;s
__nss_hostname_digits_dots() function, which is used by the gethostbyname()
and gethostbyname2() glibc function calls. A remote attacker able to make
an application call either of these functions could use this flaw to
execute arbitrary code with the permissions of the user running the
application. (CVE-2015-0235)

Red Hat would like to thank Qualys for reporting this issue.

All glibc users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-01-28T12:51:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-29T16:29:58.109-05:00">DRAFT</status_change>
            <status_change date="2015-02-16T04:00:06.204-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:36.881-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="glibc is earlier than 0:2.5-123.el5_11.1" test_ref="oval:org.mitre.oval:tst:137647"/>
            <criterion comment="glibc-common is earlier than 0:2.5-123.el5_11.1" test_ref="oval:org.mitre.oval:tst:137625"/>
            <criterion comment="glibc-devel is earlier than 0:2.5-123.el5_11.1" test_ref="oval:org.mitre.oval:tst:137702"/>
            <criterion comment="glibc-headers is earlier than 0:2.5-123.el5_11.1" test_ref="oval:org.mitre.oval:tst:137627"/>
            <criterion comment="glibc-utils is earlier than 0:2.5-123.el5_11.1" test_ref="oval:org.mitre.oval:tst:137721"/>
            <criterion comment="nscd is earlier than 0:2.5-123.el5_11.1" test_ref="oval:org.mitre.oval:tst:137572"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="glibc-debuginfo is earlier than 0:2.5-123.el5_11.1" test_ref="oval:org.mitre.oval:tst:137530"/>
            <criterion comment="glibc-debuginfo-common is earlier than 0:2.5-123.el5_11.1" test_ref="oval:org.mitre.oval:tst:137694"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28326" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1768 -- php53 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>php53</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1768.html" ref_id="RHSA-2014:1768"/>
        <reference source="CESA-2014:1768" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-October/020724.html" ref_id="CESA-2014:1768"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3668" ref_id="CVE-2014-3668"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3669" ref_id="CVE-2014-3669"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3670" ref_id="CVE-2014-3670"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3710" ref_id="CVE-2014-3710"/>
        <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A buffer overflow flaw was found in the Exif extension. A specially crafted
JPEG or TIFF file could cause a PHP application using the exif_thumbnail()
function to crash or, possibly, execute arbitrary code with the privileges
of the user running that PHP application. (CVE-2014-3670)

An integer overflow flaw was found in the way custom objects were
unserialized. Specially crafted input processed by the unserialize()
function could cause a PHP application to crash. (CVE-2014-3669)

An out-of-bounds read flaw was found in the way the File Information
(fileinfo) extension parsed Executable and Linkable Format (ELF) files.
A remote attacker could use this flaw to crash a PHP application using
fileinfo via a specially crafted ELF file. (CVE-2014-3710)

An out of bounds read flaw was found in the way the xmlrpc extension parsed
dates in the ISO 8601 format. A specially crafted XML-RPC request or
response could possibly cause a PHP application to crash. (CVE-2014-3668)

The CVE-2014-3710 issue was discovered by Francisco Alonso of Red Hat
Product Security.

All php53 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:37:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:35:56.905-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:31.859-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:35.456-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php53 is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:136192"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:136067"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:136117"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:135938"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:136160"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:136244"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:136138"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:136008"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:136303"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:136143"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:136121"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:136089"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:136277"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:136299"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:135553"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:135870"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:136136"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:136125"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:136285"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:136132"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:136230"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="php53-debuginfo is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:136292"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28295" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1959 -- kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1959.html" ref_id="RHSA-2014:1959"/>
        <reference source="CESA-2014:1959" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020806.html" ref_id="CESA-2014:1959"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0181" ref_id="CVE-2014-0181"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* It was found that the permission checks performed by the Linux kernel
when a netlink message was received were not sufficient. A local,
unprivileged user could potentially bypass these restrictions by passing a
netlink socket as stdout or stderr to a more privileged process and
altering the output of this process. (CVE-2014-0181, Moderate)

Red Hat would like to thank Andy Lutomirski for reporting this issue.

This update also fixes the following bugs:

* Previously, the kernel did not successfully deliver multicast packets
when the multicast querier was disabled. Consequently, the corosync utility
terminated unexpectedly and the affected storage node did not join its
intended cluster. With this update, multicast packets are delivered
properly when the multicast querier is disabled, and corosync handles the
node as expected. (BZ#902454)

* Previously, the kernel wrote the metadata contained in all system
information blocks on a single page of the /proc/sysinfo file. However,
when the machine configuration was very extensive and the data did not fit
on a single page, the system overwrote random memory regions, which in turn
caused data corruption when reading the /proc/sysconf file. With this
update, /proc/sysinfo automatically allocates a larger buffer if the data
output does not fit the current buffer, which prevents the data corruption.
(BZ#1131283)

* Prior to this update, the it_real_fn() function did not, in certain
cases, successfully acquire the SIGLOCK signal when the do_setitimer()
function used the ITIMER_REAL timer. As a consequence, the current process
entered an endless loop and became unresponsive. This update fixes the bug
and it_real_fn() no longer causes the kernel to become unresponsive.
(BZ#1134654)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:37:35">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:35:57.785-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:28.838-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:32.588-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:136038"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135987"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:136000"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135097"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135677"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:136019"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135986"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135065"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135585"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135933"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-PAE-debuginfo is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135853"/>
            <criterion comment="kernel-debug-debuginfo is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:136027"/>
            <criterion comment="kernel-debuginfo is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135967"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135642"/>
            <criterion comment="kernel-xen-debuginfo is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135295"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28256" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0839 -- postfix security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>postfix</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0839.html" ref_id="RHSA-2008:0839"/>
        <reference source="CESA-2008:0839" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-August/015185.html" ref_id="CESA-2008:0839-CentOS 3"/>
        <reference source="CESA-2008:0839" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-August/015187.html" ref_id="CESA-2008:0839-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2936" ref_id="CVE-2008-2936"/>
        <description>Updated postfix packages that fix a security issue are now available for
Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL),
and TLS.
A flaw was found in the way Postfix dereferences symbolic links. If a local
user has write access to a mail spool directory with no root mailbox, it
may be possible for them to append arbitrary data to files that root has
write permission to. (CVE-2008-2936)
Red Hat would like to thank Sebastian Krahmer for responsibly disclosing
this issue.
All users of postfix should upgrade to these updated packages, which
contain a backported patch that resolves this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:50.001-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:08.913-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:11.386-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 3 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="postfix is earlier than 2:2.0.16-14.1.RHEL3" test_ref="oval:org.mitre.oval:tst:139219"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postfix is earlier than 2:2.2.10-1.2.1.el4_7" test_ref="oval:org.mitre.oval:tst:138999"/>
            <criterion comment="postfix-pflogsumm is earlier than 2:2.2.10-1.2.1.el4_7" test_ref="oval:org.mitre.oval:tst:138922"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postfix is earlier than 2:2.3.3-2.1.el5_2" test_ref="oval:org.mitre.oval:tst:138734"/>
            <criterion comment="postfix-pflogsumm is earlier than 2:2.3.3-2.1.el5_2" test_ref="oval:org.mitre.oval:tst:139225"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11782" version="7" class="inventory">
      <metadata>
        <title>The operating system installed on the system is Red Hat Enterprise Linux 3</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:redhat:enterprise_linux:3"/>
        <description>The operating system installed on the system is Red Hat Enterprise Linux 3.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-06T12:00:00.000-06:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:25.361-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:36.365-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:26.996-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:11298 - Updated CPE reference, updated regular expression" date="2011-02-17T13:32:00.706-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-02-17T13:33:54.219-05:00">INTERIM</status_change>
            <status_change date="2011-03-07T04:00:05.947-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:11298 - Corrected - right version for brlapi and brlapi-devel as specified by RHSA-2010:0181-5" date="2013-03-18T12:26:00.995-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-18T12:31:17.613-04:00">INTERIM</status_change>
            <status_change date="2013-04-08T04:00:07.318-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Red Hat Enterprise 3 is installed" test_ref="oval:org.mitre.oval:tst:7836"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28242" version="3" class="patch">
      <metadata>
        <title>RHSA-2008:0897 -- ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 5</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0897.html" ref_id="RHSA-2008:0897"/>
        <reference source="CESA-2008:0897" ref_url="http://lists.centos.org/pipermail/centos-announce/2008-October/015340.html" ref_id="CESA-2008:0897-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1145" ref_id="CVE-2008-1145"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3443" ref_id="CVE-2008-3443"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3655" ref_id="CVE-2008-3655"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3656" ref_id="CVE-2008-3656"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3657" ref_id="CVE-2008-3657"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3790" ref_id="CVE-2008-3790"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3905" ref_id="CVE-2008-3905"/>
        <description>Updated ruby packages that fix several security issues are now available
for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Ruby is an interpreted scripting language for quick and easy
object-oriented programming.
The Ruby DNS resolver library, resolv.rb, used predictable transaction IDs
and a fixed source port when sending DNS requests. A remote attacker could
use this flaw to spoof a malicious reply to a DNS query. (CVE-2008-3905)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:54:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:30:40.574-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:07.937-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:10.368-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:138944"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:139094"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:138539"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:138743"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:139115"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:138826"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:138920"/>
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:139089"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:138895"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 4 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:138873"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:138996"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:138888"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:138998"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:139098"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:138414"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:138924"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11831" version="7" class="inventory">
      <metadata>
        <title>The operating system installed on the system is Red Hat Enterprise Linux 4</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:redhat:enterprise_linux:4"/>
        <description>The operating system installed on the system is Red Hat Enterprise Linux 4.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-06T12:00:00.000-06:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:25.710-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:42.275-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:34.417-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11831 - Updated CPE reference, updated regular expression" date="2011-02-17T13:29:00.547-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-02-17T13:31:01.582-05:00">INTERIM</status_change>
            <status_change date="2011-03-07T04:00:06.261-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:11366 - Corrected - right version for brlapi and brlapi-devel as specified by RHSA-2010:0181-5" date="2013-03-18T12:26:00.995-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-18T12:31:11.966-04:00">INTERIM</status_change>
            <status_change date="2013-04-08T04:00:07.616-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Red Hat Enterprise 4 is installed" test_ref="oval:org.mitre.oval:tst:2652"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28186" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1824 -- php security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1824.html" ref_id="RHSA-2014:1824"/>
        <reference source="CESA-2014:1824" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-November/020743.html" ref_id="CESA-2014:1824"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3669" ref_id="CVE-2014-3669"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3670" ref_id="CVE-2014-3670"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8626" ref_id="CVE-2014-8626"/>
        <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A buffer overflow flaw was found in the Exif extension. A specially crafted
JPEG or TIFF file could cause a PHP application using the exif_thumbnail()
function to crash or, possibly, execute arbitrary code with the privileges
of the user running that PHP application. (CVE-2014-3670)

A stack-based buffer overflow flaw was found in the way the xmlrpc
extension parsed dates in the ISO 8601 format. A specially crafted XML-RPC
request or response could possibly cause a PHP application to crash.
(CVE-2014-8626)

An integer overflow flaw was found in the way custom objects were
unserialized. Specially crafted input processed by the unserialize()
function could cause a PHP application to crash. (CVE-2014-3669)

All php users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:37:49">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:35:54.796-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:23.347-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:27.056-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135711"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135956"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135782"/>
            <criterion comment="php-common is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:136200"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:136140"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:136150"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135238"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135806"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135302"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135670"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:136076"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:136016"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:136162"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135968"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:136179"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:136014"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:136015"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:136197"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:136056"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="php-debuginfo is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135391"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28139" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1948 -- nss, nss-util, and nss-softokn security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>nss</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1948.html" ref_id="RHSA-2014:1948"/>
        <reference source="CESA-2014:1948-CentOS 5" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020795.html" ref_id="CESA-2014:1948-CentOS 5"/>
        <reference source="CESA-2014:1948-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020800.html" ref_id="CESA-2014:1948-CentOS 6"/>
        <reference source="CESA-2014:1948-CentOS 7" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020802.html" ref_id="CESA-2014:1948-CentOS 7"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

This update adds support for the TLS Fallback Signaling Cipher Suite Value
(TLS_FALLBACK_SCSV), which can be used to prevent protocol downgrade
attacks against applications which re-connect using a lower SSL/TLS
protocol version when the initial connection indicating the highest
supported protocol version fails.

This can prevent a forceful downgrade of the communication to SSL 3.0.
The SSL 3.0 protocol was found to be vulnerable to the padding oracle
attack when using block cipher suites in cipher block chaining (CBC) mode.
This issue is identified as CVE-2014-3566, and also known under the alias
POODLE. This SSL 3.0 protocol flaw will not be addressed in a future
update; it is recommended that users configure their applications to
require at least TLS protocol version 1.0 for secure communication.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:37:39">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:35:56.040-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:22.423-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:25.255-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="nss-debuginfo is earlier than 0:3.16.2.3-1.el5_11" test_ref="oval:org.mitre.oval:tst:136028"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-devel is earlier than 0:3.16.2.3-1.el5_11" test_ref="oval:org.mitre.oval:tst:135848"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.2.3-1.el5_11" test_ref="oval:org.mitre.oval:tst:136054"/>
            <criterion comment="nss is earlier than 0:3.16.2.3-1.el5_11" test_ref="oval:org.mitre.oval:tst:135977"/>
            <criterion comment="nss-tools is earlier than 0:3.16.2.3-1.el5_11" test_ref="oval:org.mitre.oval:tst:135637"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss is earlier than 0:3.16.2.3-3.el6_6" test_ref="oval:org.mitre.oval:tst:135785"/>
            <criterion comment="nss-devel is earlier than 0:3.16.2.3-3.el6_6" test_ref="oval:org.mitre.oval:tst:135612"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.2.3-3.el6_6" test_ref="oval:org.mitre.oval:tst:135957"/>
            <criterion comment="nss-sysinit is earlier than 0:3.16.2.3-3.el6_6" test_ref="oval:org.mitre.oval:tst:135709"/>
            <criterion comment="nss-tools is earlier than 0:3.16.2.3-3.el6_6" test_ref="oval:org.mitre.oval:tst:135854"/>
            <criterion comment="nss-util is earlier than 0:3.16.2.3-2.el6_6" test_ref="oval:org.mitre.oval:tst:135104"/>
            <criterion comment="nss-util-devel is earlier than 0:3.16.2.3-2.el6_6" test_ref="oval:org.mitre.oval:tst:135877"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-debuginfo is earlier than 0:3.16.2.3-3.el6_6" test_ref="oval:org.mitre.oval:tst:135108"/>
            <criterion comment="nss-util-debuginfo is earlier than 0:3.16.2.3-2.el6_6" test_ref="oval:org.mitre.oval:tst:136106"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss is earlier than 0:3.16.2.3-2.el7_0" test_ref="oval:org.mitre.oval:tst:135157"/>
            <criterion comment="nss-devel is earlier than 0:3.16.2.3-2.el7_0" test_ref="oval:org.mitre.oval:tst:135718"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.2.3-2.el7_0" test_ref="oval:org.mitre.oval:tst:135216"/>
            <criterion comment="nss-softokn is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:135941"/>
            <criterion comment="nss-softokn-devel is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:136093"/>
            <criterion comment="nss-softokn-freebl is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:135797"/>
            <criterion comment="nss-softokn-freebl-devel is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:135679"/>
            <criterion comment="nss-sysinit is earlier than 0:3.16.2.3-2.el7_0" test_ref="oval:org.mitre.oval:tst:136072"/>
            <criterion comment="nss-tools is earlier than 0:3.16.2.3-2.el7_0" test_ref="oval:org.mitre.oval:tst:136083"/>
            <criterion comment="nss-util is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:136049"/>
            <criterion comment="nss-util-devel is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:136065"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-debuginfo is earlier than 0:3.16.2.3-2.el7_0" test_ref="oval:org.mitre.oval:tst:135936"/>
            <criterion comment="nss-softokn-debuginfo is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:136085"/>
            <criterion comment="nss-util-debuginfo is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:136207"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27983" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1919 -- firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1919.html" ref_id="RHSA-2014:1919"/>
        <reference source="CESA-2014:1919-CentOS 5" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020796.html" ref_id="CESA-2014:1919-CentOS 5"/>
        <reference source="CESA-2014:1919-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020798.html" ref_id="CESA-2014:1919-CentOS 6"/>
        <reference source="CESA-2014:1919-CentOS 7" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020801.html" ref_id="CESA-2014:1919-CentOS 7"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1587" ref_id="CVE-2014-1587"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1590" ref_id="CVE-2014-1590"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1592" ref_id="CVE-2014-1592"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1593" ref_id="CVE-2014-1593"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1594" ref_id="CVE-2014-1594"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1587, CVE-2014-1590, CVE-2014-1592, CVE-2014-1593)

A flaw was found in the Alarm API, which could allow applications to
schedule actions to be run in the future. A malicious web application could
use this flaw to bypass the same-origin policy. (CVE-2014-1594)

This update disables SSL 3.0 support by default in Firefox. Details on how
to re-enable SSL 3.0 support are available at:
&lt;A HREF="https://access.redhat.com/articles/1283153">https://access.redhat.com/articles/1283153&lt;/A>

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Randell Jesup, Nils Ohlmeier, Jesse
Ruderman, Max Jonas Werner, Joe Vennix, Berend-Jan Wever, Abhishek Arya,
and Boris Zbarsky as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 31.3.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 31.3.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:37:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:36:13.137-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:17.552-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:19.079-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:31.3.0-4.el5_11" test_ref="oval:org.mitre.oval:tst:135966"/>
            <criterion comment="firefox-debuginfo is earlier than 0:31.3.0-4.el5_11" test_ref="oval:org.mitre.oval:tst:135920"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:31.3.0-3.el6_6" test_ref="oval:org.mitre.oval:tst:135624"/>
            <criterion comment="firefox-debuginfo is earlier than 0:31.3.0-3.el6_6" test_ref="oval:org.mitre.oval:tst:135768"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:31.3.0-3.el7_0" test_ref="oval:org.mitre.oval:tst:135952"/>
            <criterion comment="firefox-debuginfo is earlier than 0:31.3.0-3.el7_0" test_ref="oval:org.mitre.oval:tst:135350"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:31.3.0-4.el5.centos" test_ref="oval:org.mitre.oval:tst:135742"/>
        </criteria>
        <criteria comment="CentOS Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criterion comment="firefox is earlier than 0:31.3.0-3.el6.centos" test_ref="oval:org.mitre.oval:tst:135687"/>
        </criteria>
        <criteria comment="CentOS Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          <criterion comment="firefox is earlier than 0:31.3.0-3.el7.centos" test_ref="oval:org.mitre.oval:tst:136031"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27716" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1893 -- libXfont security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>libXfont</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1893.html" ref_id="RHSA-2014:1893"/>
        <reference source="CESA-2014:1893" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-November/020782.html" ref_id="CESA-2014:1893"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0209" ref_id="CVE-2014-0209"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0210" ref_id="CVE-2014-0210"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0211" ref_id="CVE-2014-0211"/>
        <description>The libXfont packages provide the X.Org libXfont runtime library. X.Org is
an open source implementation of the X Window System.

A use-after-free flaw was found in the way libXfont processed certain font
files when attempting to add a new directory to the font path. A malicious,
local user could exploit this issue to potentially execute arbitrary code
with the privileges of the X.Org server. (CVE-2014-0209)

Multiple out-of-bounds write flaws were found in the way libXfont parsed
replies received from an X.org font server. A malicious X.org server could
cause an X client to crash or, possibly, execute arbitrary code with the
privileges of the X.Org server. (CVE-2014-0210, CVE-2014-0211)

Red Hat would like to thank the X.org project for reporting these issues.
Upstream acknowledges Ilja van Sprundel as the original reporter.

Users of libXfont should upgrade to these updated packages, which contain a
backported patch to resolve this issue. All running X.Org server instances
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:37:43">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:35:50.639-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:13.260-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:14.016-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="libXfont-debuginfo is earlier than 0:1.2.2-1.0.6.el5_11" test_ref="oval:org.mitre.oval:tst:135960"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libXfont-devel is earlier than 0:1.2.2-1.0.6.el5_11" test_ref="oval:org.mitre.oval:tst:135703"/>
            <criterion comment="libXfont is earlier than 0:1.2.2-1.0.6.el5_11" test_ref="oval:org.mitre.oval:tst:135852"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27707" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1885 -- libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1885.html" ref_id="RHSA-2014:1885"/>
        <reference source="CESA-2014:1885" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-November/020775.html" ref_id="CESA-2014:1885"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3660" ref_id="CVE-2014-3660"/>
        <description>The libxml2 library is a development toolbox providing the implementation
of various XML standards.

A denial of service flaw was found in libxml2, a library providing support
to read, modify and write XML and HTML files. A remote attacker could
provide a specially crafted XML file that, when processed by an application
using libxml2, would lead to excessive CPU consumption (denial of service)
based on excessive entity substitutions, even if entity substitution was
disabled, which is the parser default behavior. (CVE-2014-3660)

All libxml2 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. The desktop must be
restarted (log out, then log back in) for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:37:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:36:06.680-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:12.981-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:13.780-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="libxml2-debuginfo is earlier than 0:2.6.26-2.1.25.el5_11" test_ref="oval:org.mitre.oval:tst:136070"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.25.el5_11" test_ref="oval:org.mitre.oval:tst:136057"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.25.el5_11" test_ref="oval:org.mitre.oval:tst:135895"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.25.el5_11" test_ref="oval:org.mitre.oval:tst:136030"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27220" version="5" class="patch">
      <metadata>
        <title>RHSA-2013:1353 -- sudo security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1353.html" ref_id="RHSA-2013:1353"/>
        <reference source="CESA-2013:1353" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2013-October/000877.html" ref_id="CESA-2013:1353"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1775" ref_id="CVE-2013-1775"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1776" ref_id="CVE-2013-1776"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2776" ref_id="CVE-2013-2776"/>
        <description><![CDATA[The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root.

A flaw was found in the way sudo handled time stamp files. An attacker able
to run code as a local user and with the ability to control the system
clock could possibly gain additional privileges by running commands that
the victim user was allowed to run via sudo, without knowing the victim&#39;s
password. (CVE-2013-1775)

It was found that sudo did not properly validate the controlling terminal
device when the tty_tickets option was enabled in the /etc/sudoers file. An
attacker able to run code as a local user could possibly gain additional
privileges by running commands that the victim user was allowed to run via
sudo, without knowing the victim&#39;s password. (CVE-2013-1776, CVE-2013-2776)

This update also fixes the following bugs:

* Due to a bug in the cycle detection algorithm of the visudo utility,
visudo incorrectly evaluated certain alias definitions in the /etc/sudoers
file as cycles. Consequently, a warning message about undefined aliases
appeared. This bug has been fixed, /etc/sudoers is now parsed correctly by
visudo and the warning message no longer appears. (BZ#849679)

* Previously, the &#39;sudo -l&#39; command did not parse the /etc/sudoers file
correctly if it contained an Active Directory (AD) group. The file was
parsed only up to the first AD group information and then the parsing
failed with the following message:

    sudo: unable to cache group ADDOM\admingroup, already exists

With this update, the underlying code has been modified and &#39;sudo -l&#39; now
parses /etc/sudoers containing AD groups correctly. (BZ#855836)

* Previously, the sudo utility did not escape the backslash characters
contained in user names properly. Consequently, if a system used sudo
integrated with LDAP or Active Directory (AD) as the primary authentication
mechanism, users were not able to authenticate on that system. With this
update, sudo has been modified to process LDAP and AD names correctly and
the authentication process now works as expected. (BZ#869287)

* Prior to this update, the &#39;visudo -s (strict)&#39; command incorrectly parsed
certain alias definitions. Consequently, an error message was issued. The
bug has been fixed, and parsing errors no longer occur when using &#39;visudo
-s&#39;. (BZ#905624)

All sudo users are advised to upgrade to this updated package, which
contains backported patches to correct these issues.]]></description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:14:43">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:55.857-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:58.762-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:43.911-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27220 - Updated States &amp; Objects" date="2015-02-02T15:56:00.526-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-02T16:00:50.808-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:00:55.894-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="sudo is earlier than 0:1.7.2p1-28.el5" test_ref="oval:org.mitre.oval:tst:125109"/>
            <criterion comment="sudo-debuginfo is earlier than 0:1.7.2p1-28.el5" test_ref="oval:org.mitre.oval:tst:126039"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="sudo is earlier than 0:1.7.2p1-28.el5" test_ref="oval:org.mitre.oval:tst:125109"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27210" version="3" class="patch">
      <metadata>
        <title>RHSA-2012:0304 -- vixie-cron security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>vixie-cron</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0304.html" ref_id="RHSA-2012:0304"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0424" ref_id="CVE-2010-0424"/>
        <description><![CDATA[The vixie-cron package contains the Vixie version of cron. Cron is a
standard UNIX daemon that runs specified programs at scheduled times. The
vixie-cron package adds improved security and more powerful configuration
options to the standard version of cron.

A race condition was found in the way the crontab program performed file
time stamp updates on a temporary file created when editing a user crontab
file. A local attacker could use this flaw to change the modification time
of arbitrary system files via a symbolic link attack. (CVE-2010-0424)

Red Hat would like to thank Dan Rosenberg for reporting this issue.

This update also fixes the following bugs:

* Cron jobs of users with home directories mounted on a Lightweight
Directory Access Protocol (LDAP) server or Network File System (NFS) were
often refused because jobs were marked as orphaned (typically due to a
temporary NSS lookup failure, when NIS and LDAP servers were unreachable).
With this update, a database of orphans is created, and cron jobs are
performed as expected. (BZ#455664)

* Previously, cron did not log any errors if a cron job file located in the
/etc/cron.d/ directory contained invalid entries. An upstream patch has
been applied to address this problem and invalid entries in the cron job
files now produce warning messages. (BZ#460070)

* Previously, the &quot;@reboot&quot; crontab macro incorrectly ran jobs when the
crond daemon was restarted. If the user used the macro on multiple
machines, all entries with the &quot;@reboot&quot; option were executed every time
the crond daemon was restarted. With this update, jobs are executed only
when the machine is rebooted. (BZ#476972)

* The crontab utility is now compiled as a position-independent executable
(PIE), which enhances the security of the system. (BZ#480930)

* When the parent crond daemon was stopped, but a child crond daemon was
running (executing a program), the &quot;service crond status&quot; command
incorrectly reported that crond was running. The source code has been
modified, and the &quot;service crond status&quot; command now correctly reports that
crond is stopped. (BZ#529632)

* According to the pam(8) manual page, the cron daemon, crond, supports
access control with PAM (Pluggable Authentication Module). However, the PAM
configuration file for crond did not export environment variables correctly
and, consequently, setting PAM variables via cron did not work. This update
includes a corrected /etc/pam.d/crond file that exports environment
variables correctly. Setting pam variables via cron now works as documented
in the pam(8) manual page. (BZ#541189)

* Previously, the mcstransd daemon modified labels for the crond daemon.
When the crond daemon attempted to use the modified label and mcstransd was
not running, crond used an incorrect label. Consequently, Security-Enhanced
Linux (SELinux) denials filled up the cron log, no jobs were executed, and
crond had to be restarted. With this update, both mcstransd and crond use
raw SELinux labels, which prevents the problem. (BZ#625016)

* Previously, the crontab(1) and cron(8) manual pages contained multiple
typographical errors. This update fixes those errors. (BZ#699620,
BZ#699621)

In addition, this update adds the following enhancement:

* Previously, the crontab utility did not use the Pluggable Authentication
Module (PAM) for verification of users. As a consequence, a user could
access crontab even if access had been restricted (usually by being denied
in the access.conf file). With this update, crontab returns an error
message that the user is not allowed to access crontab because of PAM
configuration. (BZ#249512)

All vixie-cron users should upgrade to this updated package, which resolves
these issues and adds this enhancement.]]></description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:14:47">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:42.583-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:57.739-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:43.184-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="vixie-cron is earlier than 0:4.1-81.el5" test_ref="oval:org.mitre.oval:tst:126092"/>
          <criterion comment="vixie-cron-debuginfo is earlier than 0:4.1-81.el5" test_ref="oval:org.mitre.oval:tst:125898"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27199" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:1310 -- samba3x security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>samba3x</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1310.html" ref_id="RHSA-2013:1310"/>
        <reference source="CESA-2013:1310" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2013-October/000872.html" ref_id="CESA-2013:1310"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0213" ref_id="CVE-2013-0213"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0214" ref_id="CVE-2013-0214"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4124" ref_id="CVE-2013-4124"/>
        <description>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

It was discovered that the Samba Web Administration Tool (SWAT) did not
protect against being opened in a web page frame. A remote attacker could
possibly use this flaw to conduct a clickjacking attack against SWAT users
or users with an active SWAT session. (CVE-2013-0213)

A flaw was found in the Cross-Site Request Forgery (CSRF) protection
mechanism implemented in SWAT. An attacker with the knowledge of a victim&amp;#39;s
password could use this flaw to bypass CSRF protections and conduct a CSRF
attack against the victim SWAT user. (CVE-2013-0214)

An integer overflow flaw was found in the way Samba handled an Extended
Attribute (EA) list provided by a client. A malicious client could send a
specially crafted EA list that triggered an overflow, causing the server to
loop and reprocess the list using an excessive amount of memory.
(CVE-2013-4124)

Note: This issue did not affect the default configuration of the Samba
server.

Red Hat would like to thank the Samba project for reporting CVE-2013-0213
and CVE-2013-0214. Upstream acknowledges Jann Horn as the original reporter
of CVE-2013-0213 and CVE-2013-0214.

These updated samba3x packages also include numerous bug fixes. Space
precludes documenting all of these changes in this advisory. Users are
directed to the Red Hat Enterprise Linux 5.10 Technical Notes, linked to in
the References, for information on the most significant of these changes.

All samba3x users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:14:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:58.531-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:57.166-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:42.880-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="samba3x-debuginfo is earlier than 0:3.6.6-0.136.el5" test_ref="oval:org.mitre.oval:tst:125923"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.136.el5" test_ref="oval:org.mitre.oval:tst:125737"/>
            <criterion comment="samba3x is earlier than 0:3.6.6-0.136.el5" test_ref="oval:org.mitre.oval:tst:126025"/>
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.136.el5" test_ref="oval:org.mitre.oval:tst:125574"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.136.el5" test_ref="oval:org.mitre.oval:tst:125773"/>
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.136.el5" test_ref="oval:org.mitre.oval:tst:125577"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.136.el5" test_ref="oval:org.mitre.oval:tst:125808"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.136.el5" test_ref="oval:org.mitre.oval:tst:125294"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.136.el5" test_ref="oval:org.mitre.oval:tst:126076"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27183" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:1348 -- Red Hat Enterprise Linux 5 kernel update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1348.html" ref_id="RHSA-2013:1348"/>
        <reference source="CESA-2013:1348" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2013-October/000843.html" ref_id="CESA-2013:1348"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4398" ref_id="CVE-2012-4398"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* It was found that a deadlock could occur in the Out of Memory (OOM)
killer. A process could trigger this deadlock by consuming a large amount
of memory, and then causing request_module() to be called. A local,
unprivileged user could use this flaw to cause a denial of service
(excessive memory consumption). (CVE-2012-4398, Moderate)

Red Hat would like to thank Tetsuo Handa for reporting this issue.

This update also fixes numerous bugs and adds various enhancements. Refer
to the Red Hat Enterprise Linux 5.10 Release Notes for information on the
most significant of these changes, and the Technical Notes for further
information, both linked to in the References.

All Red Hat Enterprise Linux 5 users are advised to install these updated
packages, which correct this issue, and fix the bugs and add the
enhancements noted in the Red Hat Enterprise Linux 5.10 Release Notes and
Technical Notes. The system must be rebooted for this update to take
effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:14:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:40.421-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:55.460-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:42.098-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:125763"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:125944"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:125907"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:126033"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:125921"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:125588"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:125786"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:125824"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:125571"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:125592"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-PAE-debuginfo is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:125918"/>
            <criterion comment="kernel-debug-debuginfo is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:125450"/>
            <criterion comment="kernel-debuginfo is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:126040"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:125074"/>
            <criterion comment="kernel-xen-debuginfo is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:126027"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27171" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1326: php53 and php security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1326-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1326.html"/>
        <reference source="CESA" ref_id="CESA-2014:1326"/>
        <reference source="CVE" ref_id="CVE-2014-2497" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2497.html"/>
        <reference source="CVE" ref_id="CVE-2014-3587" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3587.html"/>
        <reference source="CVE" ref_id="CVE-2014-3597" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3597.html"/>
        <reference source="CVE" ref_id="CVE-2014-4670" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4670.html"/>
        <reference source="CVE" ref_id="CVE-2014-4698" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4698.html"/>
        <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server. PHP's fileinfo module provides functions used to identify a
particular file according to the type of data contained by the file.

It was found that the fix for CVE-2012-1571 was incomplete; the File
Information (fileinfo) extension did not correctly parse certain Composite
Document Format (CDF) files. A remote attacker could use this flaw to crash
a PHP application using fileinfo via a specially crafted CDF file.
(CVE-2014-3587)

A NULL pointer dereference flaw was found in the gdImageCreateFromXpm()
function of PHP's gd extension. A remote attacker could use this flaw to
crash a PHP application using gd via a specially crafted X PixMap (XPM)
file. (CVE-2014-2497)

Multiple buffer over-read flaws were found in the php_parserr() function of
PHP. A malicious DNS server or a man-in-the-middle attacker could possibly
use this flaw to execute arbitrary code as the PHP interpreter if a PHP
application used the dns_get_record() function to perform a DNS query.
(CVE-2014-3597)

Two use-after-free flaws were found in the way PHP handled certain Standard
PHP Library (SPL) Iterators and ArrayIterators. A malicious script author
could possibly use either of these flaws to disclose certain portions of
server memory. (CVE-2014-4670, CVE-2014-4698)

The CVE-2014-3597 issue was discovered by David KutГЎlek of the Red Hat
BaseOS QE.

All php53 and php users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
the updated packages, the httpd daemon must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-13T11:47:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-24T13:13:12.836-04:00">DRAFT</status_change>
            <status_change date="2014-11-10T04:02:26.696-05:00">INTERIM</status_change>
            <status_change date="2014-12-01T04:01:00.632-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125409"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125920"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125414"/>
            <criterion comment="php-common is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125361"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125832"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125124"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:124972"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125778"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125644"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125033"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125888"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125654"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125683"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125177"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125738"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125620"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125814"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125886"/>
            <criterion comment="php-process is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125813"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125507"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125661"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125746"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125406"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125614"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125697"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125873"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125900"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php53 is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125496"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:124943"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125461"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125724"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125739"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125711"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125184"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125520"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125784"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125741"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125173"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125519"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125455"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125877"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125516"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125911"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125902"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125011"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125705"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125105"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125640"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27157" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1634: java-1.6.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1634-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1634.html"/>
        <reference source="CESA" ref_id="CESA-2014:1634"/>
        <reference source="CVE" ref_id="CVE-2014-6457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6457.html"/>
        <reference source="CVE" ref_id="CVE-2014-6502" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6502.html"/>
        <reference source="CVE" ref_id="CVE-2014-6504" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6504.html"/>
        <reference source="CVE" ref_id="CVE-2014-6506" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6506.html"/>
        <reference source="CVE" ref_id="CVE-2014-6511" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6511.html"/>
        <reference source="CVE" ref_id="CVE-2014-6512" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6512.html"/>
        <reference source="CVE" ref_id="CVE-2014-6517" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6517.html"/>
        <reference source="CVE" ref_id="CVE-2014-6519" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6519.html"/>
        <reference source="CVE" ref_id="CVE-2014-6531" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6531.html"/>
        <reference source="CVE" ref_id="CVE-2014-6558" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6558.html"/>
        <description>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.

Multiple flaws were discovered in the Libraries, 2D, and Hotspot components
in OpenJDK. An untrusted Java application or applet could use these flaws
to bypass certain Java sandbox restrictions. (CVE-2014-6506, CVE-2014-6531,
CVE-2014-6502, CVE-2014-6511, CVE-2014-6504, CVE-2014-6519)

It was discovered that the StAX XML parser in the JAXP component in OpenJDK
performed expansion of external parameter entities even when external
entity substitution was disabled. A remote attacker could use this flaw to
perform XML eXternal Entity (XXE) attack against applications using the
StAX parser to parse untrusted XML documents. (CVE-2014-6517)

It was discovered that the DatagramSocket implementation in OpenJDK failed
to perform source address checks for packets received on a connected
socket. A remote attacker could use this flaw to have their packets
processed as if they were received from the expected source.
(CVE-2014-6512)

It was discovered that the TLS/SSL implementation in the JSSE component in
OpenJDK failed to properly verify the server identity during the
renegotiation following session resumption, making it possible for
malicious TLS/SSL servers to perform a Triple Handshake attack against
clients using JSSE and client certificate authentication. (CVE-2014-6457)

It was discovered that the CipherInputStream class implementation in
OpenJDK did not properly handle certain exceptions. This could possibly
allow an attacker to affect the integrity of an encrypted stream handled by
this class. (CVE-2014-6558)

The CVE-2014-6512 was discovered by Florian Weimer of Red Hat Product
Security.

This update also fixes the following bug:

* The TLS/SSL implementation in OpenJDK previously failed to handle
Diffie-Hellman (DH) keys with more than 1024 bits. This caused client
applications using JSSE to fail to establish TLS/SSL connections to servers
using larger DH keys during the connection handshake. This update adds
support for DH keys with size up to 2048 bits. (BZ#1148309)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:34.038-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:42.470-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:02:32.993-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.33-1.13.5.0.el5_11" test_ref="oval:org.mitre.oval:tst:125374"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.33-1.13.5.0.el5_11" test_ref="oval:org.mitre.oval:tst:124735"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.33-1.13.5.0.el5_11" test_ref="oval:org.mitre.oval:tst:124654"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.33-1.13.5.0.el5_11" test_ref="oval:org.mitre.oval:tst:125226"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.33-1.13.5.0.el5_11" test_ref="oval:org.mitre.oval:tst:125213"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:125380"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:125204"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:125061"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:125178"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:125277"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:125390"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:125373"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:125149"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:125224"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:125310"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27144" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1633: java-1.7.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1633-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1633.html"/>
        <reference source="CESA" ref_id="CESA-2014:1633"/>
        <reference source="CVE" ref_id="CVE-2014-6457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6457.html"/>
        <reference source="CVE" ref_id="CVE-2014-6502" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6502.html"/>
        <reference source="CVE" ref_id="CVE-2014-6504" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6504.html"/>
        <reference source="CVE" ref_id="CVE-2014-6506" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6506.html"/>
        <reference source="CVE" ref_id="CVE-2014-6511" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6511.html"/>
        <reference source="CVE" ref_id="CVE-2014-6512" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6512.html"/>
        <reference source="CVE" ref_id="CVE-2014-6517" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6517.html"/>
        <reference source="CVE" ref_id="CVE-2014-6519" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6519.html"/>
        <reference source="CVE" ref_id="CVE-2014-6531" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6531.html"/>
        <reference source="CVE" ref_id="CVE-2014-6558" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6558.html"/>
        <description>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

Multiple flaws were discovered in the Libraries, 2D, and Hotspot components
in OpenJDK. An untrusted Java application or applet could use these flaws
to bypass certain Java sandbox restrictions. (CVE-2014-6506, CVE-2014-6531,
CVE-2014-6502, CVE-2014-6511, CVE-2014-6504, CVE-2014-6519)

It was discovered that the StAX XML parser in the JAXP component in OpenJDK
performed expansion of external parameter entities even when external
entity substitution was disabled. A remote attacker could use this flaw to
perform XML eXternal Entity (XXE) attack against applications using the
StAX parser to parse untrusted XML documents. (CVE-2014-6517)

It was discovered that the DatagramSocket implementation in OpenJDK failed
to perform source address checks for packets received on a connected
socket. A remote attacker could use this flaw to have their packets
processed as if they were received from the expected source.
(CVE-2014-6512)

It was discovered that the TLS/SSL implementation in the JSSE component in
OpenJDK failed to properly verify the server identity during the
renegotiation following session resumption, making it possible for
malicious TLS/SSL servers to perform a Triple Handshake attack against
clients using JSSE and client certificate authentication. (CVE-2014-6457)

It was discovered that the CipherInputStream class implementation in
OpenJDK did not properly handle certain exceptions. This could possibly
allow an attacker to affect the integrity of an encrypted stream handled by
this class. (CVE-2014-6558)

The CVE-2014-6512 was discovered by Florian Weimer of Red Hat Product
Security.

This update also fixes the following bug:

* The TLS/SSL implementation in OpenJDK previously failed to handle
Diffie-Hellman (DH) keys with more than 1024 bits. This caused client
applications using JSSE to fail to establish TLS/SSL connections to servers
using larger DH keys during the connection handshake. This update adds
support for DH keys with size up to 2048 bits. (BZ#1148309)

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:29.923-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:40.585-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:02:29.483-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.71-2.5.3.1.el5_11" test_ref="oval:org.mitre.oval:tst:125307"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.71-2.5.3.1.el5_11" test_ref="oval:org.mitre.oval:tst:124937"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.71-2.5.3.1.el5_11" test_ref="oval:org.mitre.oval:tst:125095"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.71-2.5.3.1.el5_11" test_ref="oval:org.mitre.oval:tst:125228"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.71-2.5.3.1.el5_11" test_ref="oval:org.mitre.oval:tst:124403"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27140" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1647: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1647-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1647.html"/>
        <reference source="CESA" ref_id="CESA-2014:1647"/>
        <reference source="CVE" ref_id="CVE-2014-1574" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1574.html"/>
        <reference source="CVE" ref_id="CVE-2014-1577" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1577.html"/>
        <reference source="CVE" ref_id="CVE-2014-1578" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1578.html"/>
        <reference source="CVE" ref_id="CVE-2014-1581" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1581.html"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1574, CVE-2014-1578, CVE-2014-1581, CVE-2014-1577)

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bobby Holley, Christian Holler, David Bolter, Byron
Campen Jon Coppeard, Holger Fuhrmannek, Abhishek Arya, and regenrecht as
the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 31.2.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 31.2.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:16.023-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:40.272-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:02:27.458-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:31.2.0-2.el5_11" test_ref="oval:org.mitre.oval:tst:125259"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:31.2.0-2.el5.centos" test_ref="oval:org.mitre.oval:tst:125147"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="thunderbird is earlier than 0:31.2.0-3.el6_6" test_ref="oval:org.mitre.oval:tst:125043"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27120" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:1323 -- ccid security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>ccid</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1323.html" ref_id="RHSA-2013:1323"/>
        <reference source="CESA-2013:1323" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2013-October/000828.html" ref_id="CESA-2013:1323"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4530" ref_id="CVE-2010-4530"/>
        <description>Chip/Smart Card Interface Devices (CCID) is a USB smart card reader
standard followed by most modern smart card readers. The ccid package
provides a Generic, USB-based CCID driver for readers, which follow this
standard.

An integer overflow, leading to an array index error, was found in the way
the CCID driver processed a smart card&amp;#39;s serial number. A local attacker
could use this flaw to execute arbitrary code with the privileges of the
user running the PC/SC Lite pcscd daemon (root, by default), by inserting a
specially-crafted smart card. (CVE-2010-4530)

This update also fixes the following bug:

* The pcscd service failed to read from the SafeNet Smart Card 650 v1 when
it was inserted into a smart card reader. The operation failed with a
&amp;quot;IFDHPowerICC() PowerUp failed&amp;quot; error message. This was due to the card
taking a long time to respond with a full Answer To Reset (ATR) request,
which lead to a timeout, causing the card to fail to power up. This update
increases the timeout value so that the aforementioned request is processed
properly, and the card is powered on as expected. (BZ#907821)

All ccid users are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:14:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:47.695-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:46.092-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:37.522-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="ccid is earlier than 0:1.3.8-2.el5" test_ref="oval:org.mitre.oval:tst:126004"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="ccid-debuginfo is earlier than 0:1.3.8-2.el5" test_ref="oval:org.mitre.oval:tst:125480"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27068" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1658: java-1.6.0-sun security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1658-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1658.html"/>
        <reference source="CVE" ref_id="CVE-2014-4288" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4288.html"/>
        <reference source="CVE" ref_id="CVE-2014-6457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6457.html"/>
        <reference source="CVE" ref_id="CVE-2014-6458" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6458.html"/>
        <reference source="CVE" ref_id="CVE-2014-6492" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6492.html"/>
        <reference source="CVE" ref_id="CVE-2014-6493" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6493.html"/>
        <reference source="CVE" ref_id="CVE-2014-6502" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6502.html"/>
        <reference source="CVE" ref_id="CVE-2014-6503" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6503.html"/>
        <reference source="CVE" ref_id="CVE-2014-6504" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6504.html"/>
        <reference source="CVE" ref_id="CVE-2014-6506" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6506.html"/>
        <reference source="CVE" ref_id="CVE-2014-6511" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6511.html"/>
        <reference source="CVE" ref_id="CVE-2014-6512" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6512.html"/>
        <reference source="CVE" ref_id="CVE-2014-6515" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6515.html"/>
        <reference source="CVE" ref_id="CVE-2014-6517" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6517.html"/>
        <reference source="CVE" ref_id="CVE-2014-6531" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6531.html"/>
        <reference source="CVE" ref_id="CVE-2014-6532" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6532.html"/>
        <reference source="CVE" ref_id="CVE-2014-6558" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6558.html"/>
        <description>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2014-4288, CVE-2014-6457, CVE-2014-6458, CVE-2014-6492, CVE-2014-6493,
CVE-2014-6502, CVE-2014-6503, CVE-2014-6504, CVE-2014-6506, CVE-2014-6511,
CVE-2014-6512, CVE-2014-6515, CVE-2014-6517, CVE-2014-6531, CVE-2014-6532,
CVE-2014-6558)

The CVE-2014-6512 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide Oracle Java 6 Update 85 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:29.178-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:34.610-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:02:00.627-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27068 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:41.881-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:47.238-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.85-1jpp.3.el5_11" test_ref="oval:org.mitre.oval:tst:141202"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.85-1jpp.3.el5_11" test_ref="oval:org.mitre.oval:tst:140933"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.85-1jpp.3.el5_11" test_ref="oval:org.mitre.oval:tst:141151"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.85-1jpp.3.el5_11" test_ref="oval:org.mitre.oval:tst:141228"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.85-1jpp.3.el5_11" test_ref="oval:org.mitre.oval:tst:140660"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.85-1jpp.3.el5_11" test_ref="oval:org.mitre.oval:tst:140941"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.85-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125078"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.85-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125319"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.85-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125276"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.85-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125088"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.85-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125249"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.85-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125368"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.85-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:140874"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.85-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:141147"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.85-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:141206"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.85-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:141137"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.85-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:141080"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.85-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:140292"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27062" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0255 -- subversion security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0255.html" ref_id="RHSA-2014:0255"/>
        <reference source="CESA-2014:0255" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-March/020189.html" ref_id="CESA-2014:0255"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1968" ref_id="CVE-2013-1968"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2112" ref_id="CVE-2013-2112"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0032" ref_id="CVE-2014-0032"/>
        <description>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access to
Subversion repositories via HTTP.

A flaw was found in the way the mod_dav_svn module handled OPTIONS
requests. A remote attacker with read access to an SVN repository served
via HTTP could use this flaw to cause the httpd process that handled such a
request to crash. (CVE-2014-0032)

A flaw was found in the way Subversion handled file names with newline
characters when the FSFS repository format was used. An attacker with
commit access to an SVN repository could corrupt a revision by committing a
specially crafted file. (CVE-2013-1968)

A flaw was found in the way the svnserve tool of Subversion handled remote
client network connections. An attacker with read access to an SVN
repository served via svnserve could use this flaw to cause the svnserve
daemon to exit, leading to a denial of service. (CVE-2013-2112)

All subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, for the update to take effect, you must restart the httpd
daemon, if you are using mod_dav_svn, and the svnserve daemon, if you are
serving Subversion repositories via the svn:// protocol.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:14:35">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:56.701-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:38.486-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:34.769-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:125411"/>
            <criterion comment="subversion is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:125048"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:126009"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:125958"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:126006"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:125062"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="subversion-debuginfo is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:126061"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:125681"/>
            <criterion comment="subversion is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:126034"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:125974"/>
            <criterion comment="subversion-gnome is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:125069"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:125508"/>
            <criterion comment="subversion-kde is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:126051"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:126055"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:125809"/>
            <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:125525"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="subversion-debuginfo is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:125964"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27054" version="3" class="patch">
      <metadata>
        <title>RHSA-2012:0305 -- boost security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>boost</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0305.html" ref_id="RHSA-2012:0305"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0171" ref_id="CVE-2008-0171"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0172" ref_id="CVE-2008-0172"/>
        <description>The boost packages provide free, peer-reviewed, portable C++ source
libraries with emphasis on libraries which work well with the C++ Standard
Library.

Invalid pointer dereference flaws were found in the way the Boost regular
expression library processed certain, invalid expressions. An attacker able
to make an application using the Boost library process a specially-crafted
regular expression could cause that application to crash or, potentially,
execute arbitrary code with the privileges of the user running the
application. (CVE-2008-0171)

NULL pointer dereference flaws were found in the way the Boost regular
expression library processed certain, invalid expressions. An attacker able
to make an application using the Boost library process a specially-crafted
regular expression could cause that application to crash. (CVE-2008-0172)

Red Hat would like to thank Will Drewry for reporting these issues.

This update also fixes the following bugs:

* Prior to this update, the construction of a regular expression object
could fail when several regular expression objects were created
simultaneously, such as in a multi-threaded program. With this update, the
object variables have been moved from the shared memory to the stack. Now,
the constructing function is thread safe. (BZ#472384)

* Prior to this update, header files in several Boost libraries contained
preprocessor directives that the GNU Compiler Collection (GCC) 4.4 could
not handle. This update instead uses equivalent constructs that are
standard C. (BZ#567722)

All users of boost are advised to upgrade to these updated packages, which
fix these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:14:47">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:51.899-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:37.552-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:34.507-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="boost-debuginfo is earlier than 0:1.33.1-15.el5" test_ref="oval:org.mitre.oval:tst:125852"/>
          <criterion comment="boost-devel is earlier than 0:1.33.1-15.el5" test_ref="oval:org.mitre.oval:tst:126058"/>
          <criterion comment="boost is earlier than 0:1.33.1-15.el5" test_ref="oval:org.mitre.oval:tst:125830"/>
          <criterion comment="boost-doc is earlier than 0:1.33.1-15.el5" test_ref="oval:org.mitre.oval:tst:126070"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27014" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1653: openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1653-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1653.html"/>
        <reference source="CESA" ref_id="CESA-2014:1653"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3566" ref_id="CVE-2014-3566"/>
        <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL),
Transport Layer Security (TLS), and Datagram Transport Layer Security
(DTLS) protocols, as well as a full-strength, general purpose cryptography
library.

This update adds support for the TLS Fallback Signaling Cipher Suite Value
(TLS_FALLBACK_SCSV), which can be used to prevent protocol downgrade
attacks against applications which re-connect using a lower SSL/TLS
protocol version when the initial connection indicating the highest
supported protocol version fails.

This can prevent a forceful downgrade of the communication to SSL 3.0.
The SSL 3.0 protocol was found to be vulnerable to the padding oracle
attack when using block cipher suites in cipher block chaining (CBC) mode.
This issue is identified as CVE-2014-3566, and also known under the alias
POODLE. This SSL 3.0 protocol flaw will not be addressed in a future
update; it is recommended that users configure their applications to
require at least TLS protocol version 1.0 for secure communication.

For additional information about this flaw, see the Knowledgebase article
at https://access.redhat.com/articles/1232123

All OpenSSL users are advised to upgrade to these updated packages, which
contain a backported patch to mitigate the CVE-2014-3566 issue. For the
update to take effect, all services linked to the OpenSSL library (such as
httpd and other SSL-enabled services) must be restarted or the system
rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:20.515-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:30.860-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:42.775-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27014 - Updated CVE references." date="2014-12-05T19:12:00.572-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2014-12-05T19:15:33.838-05:00">INTERIM</status_change>
            <status_change date="2014-12-22T04:00:07.197-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openssl is earlier than 0:0.9.8e-31.el5_11" test_ref="oval:org.mitre.oval:tst:125156"/>
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-31.el5_11" test_ref="oval:org.mitre.oval:tst:125322"/>
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-31.el5_11" test_ref="oval:org.mitre.oval:tst:125126"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27011" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:1319 -- sssd security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>sssd</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1319.html" ref_id="RHSA-2013:1319"/>
        <reference source="CESA-2013:1319" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2013-October/000876.html" ref_id="CESA-2013:1319"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0219" ref_id="CVE-2013-0219"/>
        <description>SSSD (System Security Services Daemon) provides a set of daemons to manage
access to remote directories and authentication mechanisms. It provides NSS
(Name Service Switch) and PAM (Pluggable Authentication Modules) interfaces
toward the system and a pluggable back end system to connect to multiple
different account sources.

A race condition was found in the way SSSD copied and removed user home
directories. A local attacker who is able to write into the home directory
of a different user who is being removed could use this flaw to perform
symbolic link attacks, possibly allowing them to modify and delete
arbitrary files with the privileges of the root user. (CVE-2013-0219)

The CVE-2013-0219 issue war discovered by Florian Weimer of the Red Hat
Product Security Team.

This update also fixes the following bugs:

* After a paging control was used, memory in the sssd_be process was never
freed which led to the growth of the sssd_be process memory usage over
time. To fix this bug, the paging control was deallocated after use, and
thus the memory usage of the sssd_be process no longer grows. (BZ#820908)

* If the sssd_be process was terminated and recreated while there were
authentication requests pending, the sssd_pam process did not recover
correctly and did not reconnect to the new sssd_be process. Consequently,
the sssd_pam process was seemingly blocked and did not accept any new
authentication requests. The sssd_pam process has been fixes so that it
reconnects to the new instance of the sssd_be process after the original
one terminated unexpectedly. Even after a crash and reconnect, the sssd_pam
process now accepts new authentication requests. (BZ#882414)

* When the sssd_be process hung for a while, it was terminated and a new
instance was created. If the old instance did not respond to the TERM
signal and continued running, SSSD terminated unexpectedly. As a
consequence, the user could not log in. SSSD now keeps track of sssd_be
subprocesses more effectively, making the restarts of sssd_be more reliable
in such scenarios. Users can now log in whenever the sssd_be is restarted
and becomes unresponsive. (BZ#886165)

* In case the processing of an LDAP request took longer than the client
timeout upon completing the request (60 seconds by default), the PAM client
could have accessed memory that was previously freed due to the client
timeout being reached. As a result, the sssd_pam process terminated
unexpectedly with a segmentation fault. SSSD now ignores an LDAP request
result when it detects that the set timeout of this request has been
reached. The sssd_pam process no longer crashes in the aforementioned
scenario. (BZ#923813)

* When there was a heavy load of users and groups to be saved in cache,
SSSD experienced a timeout. Consequently, NSS did not start the backup
process properly and it was impossible to log in. A patch has been provided
to fix this bug. The SSSD daemon now remains responsive and the login
continues as expected. (BZ#805729)

* SSSD kept the file descriptors to the log files open.  Consequently, on
occasions like moving the actual log file and restarting the back end, SSSD
still kept the file descriptors open. SSSD now closes the file descriptor
after the child process execution; after a successful back end start, the
file descriptor to log files is closed. (BZ#961680)

* While performing access control in the Identity Management back end, SSSD
erroneously downloaded the &amp;quot;member&amp;quot; attribute from the server and then
attempted to use it in the cache verbatim. Consequently, the cache
attempted to use the &amp;quot;member&amp;quot; attribute values as if they were pointing to
the local cache which was CPU intensive. The member attribute when
processing host groups is no longer downloaded and processed. Moreover, the
login process is reasonably fast even with large host groups. (BZ#979047)

All sssd users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:14:41">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:53.928-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:29.956-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:31.434-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libipa_hbac is earlier than 0:1.5.1-70.el5" test_ref="oval:org.mitre.oval:tst:125995"/>
            <criterion comment="libipa_hbac-devel is earlier than 0:1.5.1-70.el5" test_ref="oval:org.mitre.oval:tst:125740"/>
            <criterion comment="libipa_hbac-python is earlier than 0:1.5.1-70.el5" test_ref="oval:org.mitre.oval:tst:125777"/>
            <criterion comment="sssd is earlier than 0:1.5.1-70.el5" test_ref="oval:org.mitre.oval:tst:125885"/>
            <criterion comment="sssd-client is earlier than 0:1.5.1-70.el5" test_ref="oval:org.mitre.oval:tst:125482"/>
            <criterion comment="sssd-tools is earlier than 0:1.5.1-70.el5" test_ref="oval:org.mitre.oval:tst:126046"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="sssd-debuginfo is earlier than 0:1.5.1-70.el5" test_ref="oval:org.mitre.oval:tst:125564"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26975" version="3" class="patch">
      <metadata>
        <title>RHSA-2012:0303 -- xorg-x11-server security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0303.html" ref_id="RHSA-2012:0303"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4028" ref_id="CVE-2011-4028"/>
        <description>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

A flaw was found in the way the X.Org server handled lock files. A local
user with access to the system console could use this flaw to determine the
existence of a file in a directory not accessible to the user, via a
symbolic link attack. (CVE-2011-4028)

Red Hat would like to thank the researcher with the nickname vladz for
reporting this issue.

This update also fixes the following bugs:

* In rare cases, if the front and back buffer of the miDbePositionWindow()
function were not both allocated in video memory, or were both allocated in
system memory, the X Window System sometimes terminated unexpectedly. A
patch has been provided to address this issue and X no longer crashes in
the described scenario. (BZ#596899)

* Previously, when the miSetShape() function called the miRegionDestroy()
function with a NULL region, X terminated unexpectedly if the backing store
was enabled. Now, X no longer crashes in the described scenario.
(BZ#676270)

* On certain workstations running in 32-bit mode, the X11 mouse cursor
occasionally became stuck near the left edge of the X11 screen. A patch has
been provided to address this issue and the mouse cursor no longer becomes
stuck in the described scenario. (BZ#529717)

* On certain workstations with a dual-head graphics adapter using the r500
driver in Zaphod mode, the mouse pointer was confined to one monitor screen
and could not move to the other screen. A patch has been provided to
address this issue and the mouse cursor works properly across both screens.
(BZ#559964)

* Due to a double free operation, Xvfb (X virtual framebuffer) terminated
unexpectedly with a segmentation fault randomly when the last client
disconnected, that is when the server reset. This bug has been fixed in the
miDCCloseScreen() function and Xvfb no longer crashes. (BZ#674741)

* Starting the Xephyr server on an AMD64 or Intel 64 architecture with an
integrated graphics adapter caused the server to terminate unexpectedly.
This bug has been fixed in the code and Xephyr no longer crashes in the
described scenario. (BZ#454409)

* Previously, when a client made a request bigger than 1/4th of the limit
advertised in the BigRequestsEnable reply, the X server closed the
connection unexpectedly. With this update, the maxBigRequestSize variable
has been added to the code to check the size of client requests, thus
fixing this bug. (BZ#555000)

* When an X client running on a big-endian system called the
XineramaQueryScreens() function, the X server terminated unexpectedly. This
bug has been fixed in the xf86Xinerama module and the X server no longer
crashes in the described scenario. (BZ#588346)

* When installing Red Hat Enterprise Linux 5 on an IBM eServer System p
blade server, the installer did not set the correct mode on the built-in
KVM (Keyboard-Video-Mouse). Consequently, the graphical installer took a
very long time to appear and then was displayed incorrectly. A patch has
been provided to address this issue and the graphical installer now works
as expected in the described scenario. Note that this fix requires the
Red Hat Enterprise Linux 5.8 kernel update. (BZ#740497)

* Lines longer than 46,340 pixels can be drawn with one of the coordinates
being negative. However, for dashed lines, the miPolyBuildPoly() function
overflowed the &amp;quot;int&amp;quot; type when setting up edges for a section of a dashed
line. Consequently, dashed segments were not drawn at all. An upstream
patch has been applied to address this issue and dashed lines are now drawn
correctly. (BZ#649810)

All users of xorg-x11-server are advised to upgrade to these updated
packages, which correct these issues. All running X.Org server instances
must be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:14:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:50.937-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:20.451-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:29.744-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="xorg-x11-server-debuginfo is earlier than 0:1.1.1-48.90.el5" test_ref="oval:org.mitre.oval:tst:125465"/>
          <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.90.el5" test_ref="oval:org.mitre.oval:tst:125868"/>
          <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.90.el5" test_ref="oval:org.mitre.oval:tst:125839"/>
          <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.90.el5" test_ref="oval:org.mitre.oval:tst:125726"/>
          <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.90.el5" test_ref="oval:org.mitre.oval:tst:125768"/>
          <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.90.el5" test_ref="oval:org.mitre.oval:tst:125780"/>
          <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.90.el5" test_ref="oval:org.mitre.oval:tst:125436"/>
          <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.90.el5" test_ref="oval:org.mitre.oval:tst:125488"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26915" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1657: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1657-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1657.html"/>
        <reference source="CVE" ref_id="CVE-2014-4288" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4288.html"/>
        <reference source="CVE" ref_id="CVE-2014-6456" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6456.html"/>
        <reference source="CVE" ref_id="CVE-2014-6457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6457.html"/>
        <reference source="CVE" ref_id="CVE-2014-6458" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6458.html"/>
        <reference source="CVE" ref_id="CVE-2014-6476" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6476.html"/>
        <reference source="CVE" ref_id="CVE-2014-6492" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6492.html"/>
        <reference source="CVE" ref_id="CVE-2014-6493" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6493.html"/>
        <reference source="CVE" ref_id="CVE-2014-6502" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6502.html"/>
        <reference source="CVE" ref_id="CVE-2014-6503" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6503.html"/>
        <reference source="CVE" ref_id="CVE-2014-6504" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6504.html"/>
        <reference source="CVE" ref_id="CVE-2014-6506" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6506.html"/>
        <reference source="CVE" ref_id="CVE-2014-6511" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6511.html"/>
        <reference source="CVE" ref_id="CVE-2014-6512" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6512.html"/>
        <reference source="CVE" ref_id="CVE-2014-6515" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6515.html"/>
        <reference source="CVE" ref_id="CVE-2014-6517" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6517.html"/>
        <reference source="CVE" ref_id="CVE-2014-6519" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6519.html"/>
        <reference source="CVE" ref_id="CVE-2014-6527" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6527.html"/>
        <reference source="CVE" ref_id="CVE-2014-6531" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6531.html"/>
        <reference source="CVE" ref_id="CVE-2014-6532" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6532.html"/>
        <reference source="CVE" ref_id="CVE-2014-6558" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6558.html"/>
        <description>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2014-4288, CVE-2014-6456, CVE-2014-6457, CVE-2014-6458, CVE-2014-6476,
CVE-2014-6492, CVE-2014-6493, CVE-2014-6502, CVE-2014-6503, CVE-2014-6504,
CVE-2014-6506, CVE-2014-6511, CVE-2014-6512, CVE-2014-6515, CVE-2014-6517,
CVE-2014-6519, CVE-2014-6527, CVE-2014-6531, CVE-2014-6532, CVE-2014-6558)

The CVE-2014-6512 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 72 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:26.774-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:23.645-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:15.647-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26915 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:40.039-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:45.903-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.72-1jpp.4.el5_11" test_ref="oval:org.mitre.oval:tst:140719"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.72-1jpp.4.el5_11" test_ref="oval:org.mitre.oval:tst:140918"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.72-1jpp.4.el5_11" test_ref="oval:org.mitre.oval:tst:140948"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.72-1jpp.4.el5_11" test_ref="oval:org.mitre.oval:tst:141211"/>
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.72-1jpp.4.el5_11" test_ref="oval:org.mitre.oval:tst:141212"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.72-1jpp.4.el5_11" test_ref="oval:org.mitre.oval:tst:141161"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.72-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:124966"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.72-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125290"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.72-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125339"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.72-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125348"/>
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.72-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125233"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.72-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125274"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.72-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:141226"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.72-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:141191"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.72-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:140729"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.72-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:140953"/>
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.72-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:141116"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.72-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:141169"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26899" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1635: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1635-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1635.html"/>
        <reference source="CESA" ref_id="CESA-2014:1635"/>
        <reference source="CVE" ref_id="CVE-2014-1574" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1574.html"/>
        <reference source="CVE" ref_id="CVE-2014-1576" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1576.html"/>
        <reference source="CVE" ref_id="CVE-2014-1577" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1577.html"/>
        <reference source="CVE" ref_id="CVE-2014-1578" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1578.html"/>
        <reference source="CVE" ref_id="CVE-2014-1581" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1581.html"/>
        <reference source="CVE" ref_id="CVE-2014-1583" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1583.html"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1574, CVE-2014-1578, CVE-2014-1581, CVE-2014-1576,
CVE-2014-1577)

A flaw was found in the Alarm API, which allows applications to schedule
actions to be run in the future. A malicious web application could use this
flaw to bypass cross-origin restrictions. (CVE-2014-1583)

Red Hat would like to thank the Mozilla project for reporting these issues. 
Upstream acknowledges Bobby Holley, Christian Holler, David Bolter, Byron 
Campen Jon Coppeard, Atte Kettunen, Holger Fuhrmannek, Abhishek Arya, 
regenrecht, and Boris Zbarsky as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 31.2.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 31.2.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:28.428-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:22.422-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:11.417-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:31.2.0-3.el5_11" test_ref="oval:org.mitre.oval:tst:125381"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:31.2.0-3.el5.centos" test_ref="oval:org.mitre.oval:tst:125077"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 7 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner is earlier than 0:31.2.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:125354"/>
            <criterion comment="xulrunner-devel is earlier than 0:31.2.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:125313"/>
            <criterion comment="firefox is earlier than 0:31.2.0-3.el7_0" test_ref="oval:org.mitre.oval:tst:125112"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 7 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner is earlier than 0:31.2.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:125349"/>
            <criterion comment="xulrunner-devel is earlier than 0:31.2.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:125107"/>
            <criterion comment="firefox is earlier than 0:31.2.0-3.el7.centos" test_ref="oval:org.mitre.oval:tst:124713"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="firefox is earlier than 0:31.2.0-3.el6_6" test_ref="oval:org.mitre.oval:tst:125356"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26851" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1194: conga security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>conga</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1194-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1194.html"/>
        <reference source="CVE" ref_id="CVE-2012-5485" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5485.html"/>
        <reference source="CVE" ref_id="CVE-2012-5486" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5486.html"/>
        <reference source="CVE" ref_id="CVE-2012-5488" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5488.html"/>
        <reference source="CVE" ref_id="CVE-2012-5497" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5497.html"/>
        <reference source="CVE" ref_id="CVE-2012-5498" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5498.html"/>
        <reference source="CVE" ref_id="CVE-2012-5499" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5499.html"/>
        <reference source="CVE" ref_id="CVE-2012-5500" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5500.html"/>
        <reference source="CVE" ref_id="CVE-2013-6496" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6496.html"/>
        <reference source="CVE" ref_id="CVE-2014-3521" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3521.html"/>
        <reference source="CESA-2014:1194" ref_id="CESA-2014:1194" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-September/020611.html"/>
        <description>The Conga project is a management system for remote workstations.
It consists of luci, which is a secure web-based front end, and ricci,
which is a secure daemon that dispatches incoming messages to underlying
management modules.

It was discovered that Plone, included as a part of luci, did not properly
protect the administrator interface (control panel). A remote attacker
could use this flaw to inject a specially crafted Python statement or
script into Plone's restricted Python sandbox that, when the administrator
interface was accessed, would be executed with the privileges of that
administrator user. (CVE-2012-5485)

It was discovered that Plone, included as a part of luci, did not properly
sanitize HTTP headers provided within certain URL requests. A remote
attacker could use a specially crafted URL that, when processed, would
cause the injected HTTP headers to be returned as a part of the Plone HTTP
response, potentially allowing the attacker to perform other more advanced
attacks. (CVE-2012-5486)

Multiple information leak flaws were found in the way conga processed luci
site extension-related URL requests. A remote, unauthenticated attacker
could issue a specially crafted HTTP request that, when processed, would
result in unauthorized information disclosure. (CVE-2013-6496)

It was discovered that various components in the luci site
extension-related URLs were not properly restricted to administrative
users. A remote, authenticated attacker could escalate their privileges to
perform certain actions that should be restricted to administrative users,
such as adding users and systems, and viewing log data. (CVE-2014-3521)

It was discovered that Plone, included as a part of luci, did not properly
protect the privilege of running RestrictedPython scripts. A remote
attacker could use a specially crafted URL that, when processed, would
allow the attacker to submit and perform expensive computations or, in
conjunction with other attacks, be able to access or alter privileged
information. (CVE-2012-5488)

It was discovered that Plone, included as a part of luci, did not properly
enforce permissions checks on the membership database. A remote attacker
could use a specially crafted URL that, when processed, could allow the
attacker to enumerate user account names. (CVE-2012-5497)

It was discovered that Plone, included as a part of luci, did not properly
handle the processing of requests for certain collections. A remote
attacker could use a specially crafted URL that, when processed, would lead
to excessive I/O and/or cache resource consumption. (CVE-2012-5498)

It was discovered that Plone, included as a part of luci, did not properly
handle the processing of very large values passed to an internal utility
function. A remote attacker could use a specially crafted URL that, when
processed, would lead to excessive memory consumption. (CVE-2012-5499)

It was discovered that Plone, included as a part of luci, allowed a remote
anonymous user to change titles of content items due to improper
permissions checks. (CVE-2012-5500)

The CVE-2014-3521 issue was discovered by Radek Steiger of Red Hat, and the
CVE-2013-6496 issue was discovered by Jan Pokorny of Red Hat.

In addition, these updated conga packages include several bug fixes.
Space precludes documenting all of these changes in this advisory.
Users are directed to the Red Hat Enterprise Linux 5.11 Technical Notes,
linked to in the References section, for information on the most
significant of these changes

All conga users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the luci and ricci services will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:06.903-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:58.744-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:08.581-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26851 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:51.746-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:12.483-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="luci is earlier than 0:0.12.2-81.el5.centos" test_ref="oval:org.mitre.oval:tst:138442"/>
          <criterion comment="ricci is earlier than 0:0.12.2-81.el5.centos" test_ref="oval:org.mitre.oval:tst:138312"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26820" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1193: axis security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>axis</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1193-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1193.html"/>
        <reference source="CESA" ref_id="CESA-2014:1193"/>
        <reference source="CVE" ref_id="CVE-2014-3596" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3596.html"/>
        <description>Apache Axis is an implementation of SOAP (Simple Object Access Protocol).
It can be used to build both web service clients and servers.

It was discovered that Axis incorrectly extracted the host name from an
X.509 certificate subject's Common Name (CN) field. A man-in-the-middle
attacker could use this flaw to spoof an SSL server using a specially
crafted X.509 certificate. (CVE-2014-3596)

For additional information on this flaw, refer to the Knowledgebase article
in the References section.

This issue was discovered by David Jorm and Arun Neelicattu of Red Hat
Product Security.

All axis users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. Applications using Apache
Axis must be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:09.637-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:56.528-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:05.063-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="axis is earlier than 0:1.2.1-2jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:123908"/>
            <criterion comment="axis-javadoc is earlier than 0:1.2.1-2jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:123895"/>
            <criterion comment="axis-manual is earlier than 0:1.2.1-2jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:123598"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="axis is earlier than 0:1.2.1-7.5.el6_5" test_ref="oval:org.mitre.oval:tst:123761"/>
            <criterion comment="axis-javadoc is earlier than 0:1.2.1-7.5.el6_5" test_ref="oval:org.mitre.oval:tst:123903"/>
            <criterion comment="axis-manual is earlier than 0:1.2.1-7.5.el6_5" test_ref="oval:org.mitre.oval:tst:123658"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26816" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1671 -- rsyslog5 and rsyslog security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>rsyslog</product>
          <product>rsyslog5</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1671.html" ref_id="RHSA-2014:1671"/>
        <reference source="CESA-2014:1671" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-October/020699.html" ref_id="CESA-2014:1671"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3634" ref_id="CVE-2014-3634"/>
        <description>The rsyslog packages provide an enhanced, multi-threaded syslog daemon
that supports writing to relational databases, syslog/TCP, RFC 3195,
permitted sender lists, filtering on any message part, and fine grained
output format control.

A flaw was found in the way rsyslog handled invalid log message priority
values. In certain configurations, a local attacker, or a remote attacker
able to connect to the rsyslog port, could use this flaw to crash the
rsyslog daemon. (CVE-2014-3634)

Red Hat would like to thank Rainer Gerhards of rsyslog upstream for
reporting this issue.

All rsyslog5 and rsyslog users are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue. After
installing the update, the rsyslog service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:14:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:48:07.936-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:00:56.610-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:23.464-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="rsyslog5 is earlier than 0:5.8.12-5.el5_11" test_ref="oval:org.mitre.oval:tst:125788"/>
            <criterion comment="rsyslog5-gnutls is earlier than 0:5.8.12-5.el5_11" test_ref="oval:org.mitre.oval:tst:125806"/>
            <criterion comment="rsyslog5-gssapi is earlier than 0:5.8.12-5.el5_11" test_ref="oval:org.mitre.oval:tst:125803"/>
            <criterion comment="rsyslog5-mysql is earlier than 0:5.8.12-5.el5_11" test_ref="oval:org.mitre.oval:tst:125338"/>
            <criterion comment="rsyslog5-pgsql is earlier than 0:5.8.12-5.el5_11" test_ref="oval:org.mitre.oval:tst:125906"/>
            <criterion comment="rsyslog5-snmp is earlier than 0:5.8.12-5.el5_11" test_ref="oval:org.mitre.oval:tst:125639"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="rsyslog5-debuginfo is earlier than 0:5.8.12-5.el5_11" test_ref="oval:org.mitre.oval:tst:125903"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="rsyslog is earlier than 0:5.8.10-9.el6_6" test_ref="oval:org.mitre.oval:tst:125524"/>
            <criterion comment="rsyslog-gnutls is earlier than 0:5.8.10-9.el6_6" test_ref="oval:org.mitre.oval:tst:125503"/>
            <criterion comment="rsyslog-gssapi is earlier than 0:5.8.10-9.el6_6" test_ref="oval:org.mitre.oval:tst:125716"/>
            <criterion comment="rsyslog-mysql is earlier than 0:5.8.10-9.el6_6" test_ref="oval:org.mitre.oval:tst:125517"/>
            <criterion comment="rsyslog-pgsql is earlier than 0:5.8.10-9.el6_6" test_ref="oval:org.mitre.oval:tst:125341"/>
            <criterion comment="rsyslog-relp is earlier than 0:5.8.10-9.el6_6" test_ref="oval:org.mitre.oval:tst:125650"/>
            <criterion comment="rsyslog-snmp is earlier than 0:5.8.10-9.el6_6" test_ref="oval:org.mitre.oval:tst:125530"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="rsyslog-debuginfo is earlier than 0:5.8.10-9.el6_6" test_ref="oval:org.mitre.oval:tst:125854"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26777" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1245: krb5 security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1245-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1245.html"/>
        <reference source="CVE" ref_id="CVE-2013-1418" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1418.html"/>
        <reference source="CVE" ref_id="CVE-2013-6800" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6800.html"/>
        <reference source="CVE" ref_id="CVE-2014-4341" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4341.html"/>
        <reference source="CVE" ref_id="CVE-2014-4344" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4344.html"/>
        <reference source="CESA-2014:1245" ref_id="CESA-2014:1245" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-September/020626.html"/>
        <description>Kerberos is an authentication system which allows clients and services to
authenticate to each other with the help of a trusted third party, a
Kerberos Key Distribution Center (KDC).

It was found that if a KDC served multiple realms, certain requests could
cause the setup_server_realm() function to dereference a NULL pointer.
A remote, unauthenticated attacker could use this flaw to crash the KDC
using a specially crafted request. (CVE-2013-1418, CVE-2013-6800)

A NULL pointer dereference flaw was found in the MIT Kerberos SPNEGO
acceptor for continuation tokens. A remote, unauthenticated attacker could
use this flaw to crash a GSSAPI-enabled server application. (CVE-2014-4344)

A buffer over-read flaw was found in the way MIT Kerberos handled certain
requests. A man-in-the-middle attacker with a valid Kerberos ticket who is
able to inject packets into a client or server application's GSSAPI session
could use this flaw to crash the application. (CVE-2014-4341)

This update also fixes the following bugs:

* Prior to this update, the libkrb5 library occasionally attempted to free
already freed memory when encrypting credentials. As a consequence, the
calling process terminated unexpectedly with a segmentation fault.
With this update, libkrb5 frees memory correctly, which allows the
credentials to be encrypted appropriately and thus prevents the mentioned
crash. (BZ#1004632)

* Previously, when the krb5 client library was waiting for a response from
a server, the timeout variable in certain cases became a negative number.
Consequently, the client could enter a loop while checking for responses.
With this update, the client logic has been modified and the described
error no longer occurs. (BZ#1089732)

All krb5 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the krb5kdc daemon will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:13.966-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:52.744-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:01:56.399-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26777 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:54.472-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:11.889-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="krb5-debuginfo is earlier than 0:1.6.1-78.el5" test_ref="oval:org.mitre.oval:tst:138310"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="krb5-devel is earlier than 0:1.6.1-78.el5" test_ref="oval:org.mitre.oval:tst:123687"/>
            <criterion comment="krb5-server is earlier than 0:1.6.1-78.el5" test_ref="oval:org.mitre.oval:tst:123887"/>
            <criterion comment="krb5-server-ldap is earlier than 0:1.6.1-78.el5" test_ref="oval:org.mitre.oval:tst:123870"/>
            <criterion comment="krb5-libs is earlier than 0:1.6.1-78.el5" test_ref="oval:org.mitre.oval:tst:123866"/>
            <criterion comment="krb5-workstation is earlier than 0:1.6.1-78.el5" test_ref="oval:org.mitre.oval:tst:123884"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26725" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1307: nss security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 5</platform>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1307-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1307.html"/>
        <reference source="CESA-2014:1307" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-September/020595.html" ref_id="CESA-2014:1307"/>
        <reference source="CVE" ref_id="CVE-2014-1568" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1568.html"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

A flaw was found in the way NSS parsed ASN.1 (Abstract Syntax Notation One)
input from certain RSA signatures. A remote attacker could use this flaw to
forge RSA certificates by providing a specially crafted signature to an
application using NSS. (CVE-2014-1568)

Red Hat would like to thank the Mozilla project for reporting this issue.
Upstream acknowledges Antoine Delignat-Lavaud and Intel Product Security
Incident Response Team as the original reporters.

All NSS users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, applications using NSS must be restarted for this update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:12.242-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:47.524-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:01:48.079-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26725 - CentOS checks added for RHEL vulnerabilities." date="2014-11-13T08:36:00.372-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-11-13T08:48:03.128-05:00">INTERIM</status_change>
            <status_change date="2014-12-01T04:00:41.246-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="nss-debuginfo is earlier than 0:3.16.1-4.el5_11" test_ref="oval:org.mitre.oval:tst:135359"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss is earlier than 0:3.16.1-4.el5_11" test_ref="oval:org.mitre.oval:tst:123897"/>
            <criterion comment="nss-devel is earlier than 0:3.16.1-4.el5_11" test_ref="oval:org.mitre.oval:tst:123878"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.1-4.el5_11" test_ref="oval:org.mitre.oval:tst:123032"/>
            <criterion comment="nss-tools is earlier than 0:3.16.1-4.el5_11" test_ref="oval:org.mitre.oval:tst:123944"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-util is earlier than 0:3.16.1-2.el6_5" test_ref="oval:org.mitre.oval:tst:123805"/>
            <criterion comment="nss-util-devel is earlier than 0:3.16.1-2.el6_5" test_ref="oval:org.mitre.oval:tst:123768"/>
            <criterion comment="nss is earlier than 0:3.16.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:123826"/>
            <criterion comment="nss-devel is earlier than 0:3.16.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:123832"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:123883"/>
            <criterion comment="nss-sysinit is earlier than 0:3.16.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:123201"/>
            <criterion comment="nss-tools is earlier than 0:3.16.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:123954"/>
            <criterion comment="nss-softokn is earlier than 0:3.14.3-12.el6_5" test_ref="oval:org.mitre.oval:tst:123673"/>
            <criterion comment="nss-softokn-devel is earlier than 0:3.14.3-12.el6_5" test_ref="oval:org.mitre.oval:tst:123916"/>
            <criterion comment="nss-softokn-freebl is earlier than 0:3.14.3-12.el6_5" test_ref="oval:org.mitre.oval:tst:123871"/>
            <criterion comment="nss-softokn-freebl-devel is earlier than 0:3.14.3-12.el6_5" test_ref="oval:org.mitre.oval:tst:123968"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-debuginfo is earlier than 0:3.16.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:135234"/>
            <criterion comment="nss-softokn-debuginfo is earlier than 0:3.14.3-12.el6_5" test_ref="oval:org.mitre.oval:tst:135328"/>
            <criterion comment="nss-util-debuginfo is earlier than 0:3.16.1-2.el6_5" test_ref="oval:org.mitre.oval:tst:135090"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-softokn is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:124011"/>
            <criterion comment="nss-softokn-devel is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:123719"/>
            <criterion comment="nss-softokn-freebl is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:123982"/>
            <criterion comment="nss-softokn-freebl-devel is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:123896"/>
            <criterion comment="nss-util is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:123793"/>
            <criterion comment="nss-util-devel is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:123190"/>
            <criterion comment="nss is earlier than 0:3.16.2-7.el7_0" test_ref="oval:org.mitre.oval:tst:123492"/>
            <criterion comment="nss-devel is earlier than 0:3.16.2-7.el7_0" test_ref="oval:org.mitre.oval:tst:123873"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.2-7.el7_0" test_ref="oval:org.mitre.oval:tst:123650"/>
            <criterion comment="nss-sysinit is earlier than 0:3.16.2-7.el7_0" test_ref="oval:org.mitre.oval:tst:123771"/>
            <criterion comment="nss-tools is earlier than 0:3.16.2-7.el7_0" test_ref="oval:org.mitre.oval:tst:123851"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-debuginfo is earlier than 0:3.16.2-7.el7_0" test_ref="oval:org.mitre.oval:tst:134839"/>
            <criterion comment="nss-softokn-debuginfo is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:135333"/>
            <criterion comment="nss-util-debuginfo is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:135339"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26718" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1255: krb5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1255-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1255.html"/>
        <reference source="CVE" ref_id="CVE-2014-4345" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4345.html"/>
        <reference source="CESA-2014:1255" ref_id="CESA-2014:1255" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-October/020678.html"/>
        <description>Kerberos is an authentication system which allows clients and services to
authenticate to each other with the help of a trusted third party, a
Kerberos Key Distribution Center (KDC).

A buffer overflow was found in the KADM5 administration server (kadmind)
when it was used with an LDAP back end for the KDC database. A remote,
authenticated attacker could potentially use this flaw to execute arbitrary
code on the system running kadmind. (CVE-2014-4345)

All krb5 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
updated packages, the krb5kdc and kadmind daemons will be restarted
automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:03.279-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:47.362-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:01:47.589-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26718 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:55.518-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:09.685-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="krb5-debuginfo is earlier than 0:1.6.1-80.el5_11" test_ref="oval:org.mitre.oval:tst:137941"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="krb5-devel is earlier than 0:1.6.1-80.el5_11" test_ref="oval:org.mitre.oval:tst:123511"/>
            <criterion comment="krb5-server is earlier than 0:1.6.1-80.el5_11" test_ref="oval:org.mitre.oval:tst:123922"/>
            <criterion comment="krb5-server-ldap is earlier than 0:1.6.1-80.el5_11" test_ref="oval:org.mitre.oval:tst:123984"/>
            <criterion comment="krb5-libs is earlier than 0:1.6.1-80.el5_11" test_ref="oval:org.mitre.oval:tst:122986"/>
            <criterion comment="krb5-workstation is earlier than 0:1.6.1-80.el5_11" test_ref="oval:org.mitre.oval:tst:123986"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26703" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1047: nss nad nspr bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1047-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1047.html"/>
        <reference source="CVE" ref_id="CVE-2013-1740" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1740.html"/>
        <reference source="CVE" ref_id="CVE-2014-1490" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1490.html"/>
        <reference source="CVE" ref_id="CVE-2014-1491" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1491.html"/>
        <reference source="CVE" ref_id="CVE-2014-1492" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1492.html"/>
        <reference source="CVE" ref_id="CVE-2014-1545" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1545.html"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support the
cross-platform development of security-enabled client and server applications.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-08T16:42:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-17T10:44:03.809-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:00.768-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:26.054-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="nss is earlier than 0:3.16.1-2.el5" test_ref="oval:org.mitre.oval:tst:122742"/>
          <criterion comment="nss-devel is earlier than 0:3.16.1-2.el5" test_ref="oval:org.mitre.oval:tst:123083"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.1-2.el5" test_ref="oval:org.mitre.oval:tst:122829"/>
          <criterion comment="nss-tools is earlier than 0:3.16.1-2.el5" test_ref="oval:org.mitre.oval:tst:123117"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26700" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1148: squid security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>squid</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1148-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1148.html"/>
        <reference source="CESA" ref_id="CESA-2014:1148"/>
        <reference source="CVE" ref_id="CVE-2013-4115" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4115.html"/>
        <reference source="CVE" ref_id="CVE-2014-3609" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3609.html"/>
        <description>Squid is a high-performance proxy caching server for web clients,
supporting FTP, Gopher, and HTTP data objects.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-08T16:42:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-17T10:44:03.508-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:00.287-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:25.516-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.6.STABLE21-7.el5_10" test_ref="oval:org.mitre.oval:tst:122890"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="squid is earlier than 7:3.1.10-22.el6_5" test_ref="oval:org.mitre.oval:tst:122939"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26690" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1173: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1173-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1173.html"/>
        <reference source="CVE" ref_id="CVE-2014-0547" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0547.html"/>
        <reference source="CVE" ref_id="CVE-2014-0548" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0548.html"/>
        <reference source="CVE" ref_id="CVE-2014-0549" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0549.html"/>
        <reference source="CVE" ref_id="CVE-2014-0550" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0550.html"/>
        <reference source="CVE" ref_id="CVE-2014-0551" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0551.html"/>
        <reference source="CVE" ref_id="CVE-2014-0552" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0552.html"/>
        <reference source="CVE" ref_id="CVE-2014-0553" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0553.html"/>
        <reference source="CVE" ref_id="CVE-2014-0554" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0554.html"/>
        <reference source="CVE" ref_id="CVE-2014-0555" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0555.html"/>
        <reference source="CVE" ref_id="CVE-2014-0556" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0556.html"/>
        <reference source="CVE" ref_id="CVE-2014-0557" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0557.html"/>
        <reference source="CVE" ref_id="CVE-2014-0559" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0559.html"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed in the Adobe Security Bulletin APSB14-21,
listed in the References section.

Multiple flaws were found in the way flash-plugin displayed certain SWF
content. An attacker could use these flaws to create a specially crafted
SWF file that would cause flash-plugin to crash or, potentially, execute
arbitrary code when the victim loaded a page containing the malicious SWF
content. (CVE-2014-0547, CVE-2014-0549, CVE-2014-0550, CVE-2014-0551,
CVE-2014-0552, CVE-2014-0553, CVE-2014-0554, CVE-2014-0555, CVE-2014-0556,
CVE-2014-0557, CVE-2014-0559)

A flaw in flash-plugin could allow an attacker to bypass the same-origin
policy. (CVE-2014-0548)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.406.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:02.237-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:45.315-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:01:43.064-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.406-1.el5" test_ref="oval:org.mitre.oval:tst:123869"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.406-1.el6" test_ref="oval:org.mitre.oval:tst:123356"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26641" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1243: automake security update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>automake</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1243-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1243.html"/>
        <reference source="CVE" ref_id="CVE-2012-3386" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3386.html"/>
        <reference source="CESA-2014:1243" ref_id="CESA-2014:1243" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-September/020607.html"/>
        <description>Automake is a tool for automatically generating Makefile.in files compliant
with the GNU Coding Standards.

It was found that the distcheck rule in Automake-generated Makefiles made a
directory world-writable when preparing source archives. If a malicious,
local user could access this directory, they could execute arbitrary code
with the privileges of the user running "make distcheck". (CVE-2012-3386)

Red Hat would like to thank Jim Meyering for reporting this issue. Upstream
acknowledges Stefano Lattarini as the original reporter.

All automake users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:02.950-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:43.612-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:01:40.764-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26641 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:50.602-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:09.452-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="automake is earlier than 0:1.9.6-3.el5" test_ref="oval:org.mitre.oval:tst:123229"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26632" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1143: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1143-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1143.html"/>
        <reference source="CESA" ref_id="CESA-2014:1143"/>
        <reference source="CVE" ref_id="CVE-2014-3917" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3917.html"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-08T16:42:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-17T10:44:06.667-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:52.328-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:14.555-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:122988"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:122733"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:123141"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:122732"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:122313"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:122936"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:122206"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:123094"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:122572"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:123180"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:122921"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:122789"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26589" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1306: bash security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>bash</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1306-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1306.html"/>
        <reference source="CESA" ref_id="CESA-2014:1306"/>
        <reference source="CVE" ref_id="CVE-2014-7169" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-7169.html"/>
        <description>The GNU Bourne Again shell (Bash) is a shell and command language
interpreter compatible with the Bourne shell (sh). Bash is the default
shell for Red Hat Enterprise Linux.

It was found that the fix for CVE-2014-6271 was incomplete, and Bash still
allowed certain characters to be injected into other environments via
specially crafted environment variables. An attacker could potentially use
this flaw to override or bypass environment restrictions to execute shell
commands. Certain services and applications allow remote unauthenticated
attackers to provide environment variables, allowing them to exploit this
issue. (CVE-2014-7169)

Applications which directly create bash functions as environment variables
need to be made aware of changes to the way names are handled by this
update. For more information see the Knowledgebase article at
https://access.redhat.com/articles/1200223

Note: Docker users are advised to use "yum update" within their containers,
and to commit the resulting changes.

For additional information on CVE-2014-6271 and CVE-2014-7169, refer to the
aforementioned Knowledgebase article.

All bash users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:04.676-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:41.186-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:01:36.282-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bash is earlier than 0:4.1.2-15.el6_5.2" test_ref="oval:org.mitre.oval:tst:123544"/>
            <criterion comment="bash-doc is earlier than 0:4.1.2-15.el6_5.2" test_ref="oval:org.mitre.oval:tst:123461"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="bash is earlier than 0:3.2-33.el5_11.4" test_ref="oval:org.mitre.oval:tst:123086"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="bash is earlier than 0:3.2-33.el5_10.4" test_ref="oval:org.mitre.oval:tst:123949"/>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bash is earlier than 0:4.2.45-5.el7_0.4" test_ref="oval:org.mitre.oval:tst:123527"/>
            <criterion comment="bash-doc is earlier than 0:4.2.45-5.el7_0.4" test_ref="oval:org.mitre.oval:tst:123900"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26573" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1144: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1144-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1144.html"/>
        <reference source="CESA" ref_id="CESA-2014:1144"/>
        <reference source="CVE" ref_id="CVE-2014-1562" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1562.html"/>
        <reference source="CVE" ref_id="CVE-2014-1567" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1567.html"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-08T16:42:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-17T10:44:04.763-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:46.744-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:04.557-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:24.8.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:122510"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:24.8.0-2.el5.centos" test_ref="oval:org.mitre.oval:tst:123047"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="firefox is earlier than 0:24.8.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:122594"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="firefox is earlier than 0:24.8.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:123084"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 7 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:24.8.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:122819"/>
            <criterion comment="xulrunner is earlier than 0:24.8.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:122875"/>
            <criterion comment="xulrunner-devel is earlier than 0:24.8.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:122877"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 7 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:24.8.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:122891"/>
            <criterion comment="xulrunner is earlier than 0:24.8.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:122772"/>
            <criterion comment="xulrunner-devel is earlier than 0:24.8.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:123170"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26526" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1145: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1145-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1145.html"/>
        <reference source="CESA" ref_id="CESA-2014:1145"/>
        <reference source="CVE" ref_id="CVE-2014-1562" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1562.html"/>
        <reference source="CVE" ref_id="CVE-2014-1567" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1567.html"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-08T16:42:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-17T10:44:05.497-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:43.842-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:00:58.898-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:24.8.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:122759"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:24.8.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:123029"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:24.8.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:123152"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:24.8.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:122969"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26521" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1293: bash security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>bash</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1293-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1293.html"/>
        <reference source="CESA" ref_id="CESA-2014:1293"/>
        <reference source="CVE" ref_id="CVE-2014-6271" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6271.html"/>
        <description>The GNU Bourne Again shell (Bash) is a shell and command language
interpreter compatible with the Bourne shell (sh). Bash is the default
shell for Red Hat Enterprise Linux.

A flaw was found in the way Bash evaluated certain specially crafted
environment variables. An attacker could use this flaw to override or
bypass environment restrictions to execute shell commands. Certain
services and applications allow remote unauthenticated attackers to
provide environment variables, allowing them to exploit this issue.
(CVE-2014-6271)

For additional information on the CVE-2014-6271 flaw, refer to the
Knowledgebase article at https://access.redhat.com/articles/1200223

Red Hat would like to thank Stephane Chazelas for reporting this issue.

All bash users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:13.020-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:36.830-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:01:30.329-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bash is earlier than 0:4.1.2-15.el6_5.1" test_ref="oval:org.mitre.oval:tst:123932"/>
            <criterion comment="bash-doc is earlier than 0:4.1.2-15.el6_5.1" test_ref="oval:org.mitre.oval:tst:123696"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="bash is earlier than 0:3.2-33.el5.1" test_ref="oval:org.mitre.oval:tst:123953"/>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bash is earlier than 0:4.2.45-5.el7_0.2" test_ref="oval:org.mitre.oval:tst:123926"/>
            <criterion comment="bash-doc is earlier than 0:4.2.45-5.el7_0.2" test_ref="oval:org.mitre.oval:tst:123825"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26499" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1166: jakarta-commons-httpclient security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>jakarta-commons-httpclient</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1166-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1166.html"/>
        <reference source="CESA" ref_id="CESA-2014:1166"/>
        <reference source="CVE" ref_id="CVE-2014-3577" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3577.html"/>
        <description>Jakarta Commons HTTPClient implements the client side of HTTP standards.

It was discovered that the HTTPClient incorrectly extracted host name from
an X.509 certificate subject's Common Name (CN) field. A man-in-the-middle
attacker could use this flaw to spoof an SSL server using a specially
crafted X.509 certificate. (CVE-2014-3577)

For additional information on this flaw, refer to the Knowledgebase
article in the References section.

All jakarta-commons-httpclient users are advised to upgrade to these
updated packages, which contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:06.564-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:34.668-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:01:29.562-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="jakarta-commons-httpclient is earlier than 1:3.0-7jpp.4.el5_10" test_ref="oval:org.mitre.oval:tst:123818"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 1:3.0-7jpp.4.el5_10" test_ref="oval:org.mitre.oval:tst:123708"/>
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.0-7jpp.4.el5_10" test_ref="oval:org.mitre.oval:tst:123816"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 1:3.0-7jpp.4.el5_10" test_ref="oval:org.mitre.oval:tst:123791"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="jakarta-commons-httpclient is earlier than 1:3.1-0.9.el6_5" test_ref="oval:org.mitre.oval:tst:123167"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 1:3.1-0.9.el6_5" test_ref="oval:org.mitre.oval:tst:123604"/>
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.1-0.9.el6_5" test_ref="oval:org.mitre.oval:tst:122896"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 1:3.1-0.9.el6_5" test_ref="oval:org.mitre.oval:tst:123758"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="jakarta-commons-httpclient is earlier than 1:3.1-16.el7_0" test_ref="oval:org.mitre.oval:tst:123792"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 1:3.1-16.el7_0" test_ref="oval:org.mitre.oval:tst:123283"/>
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.1-16.el7_0" test_ref="oval:org.mitre.oval:tst:123770"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 1:3.1-16.el7_0" test_ref="oval:org.mitre.oval:tst:123817"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26477" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1172: procmail security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>procmail</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1172-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1172.html"/>
        <reference source="CESA" ref_id="CESA-2014:1172"/>
        <reference source="CVE" ref_id="CVE-2014-3618" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3618.html"/>
        <description>The procmail program is used for local mail delivery. In addition to just
delivering mail, procmail can be used for automatic filtering, presorting,
and other mail handling jobs.

A heap-based buffer overflow flaw was found in procmail's formail utility.
A remote attacker could send an email with specially crafted headers that,
when processed by formail, could cause procmail to crash or, possibly,
execute arbitrary code as the user running formail. (CVE-2014-3618)

All procmail users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:01.562-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:33.283-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:01:27.293-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="procmail is earlier than 0:3.22-17.1.2" test_ref="oval:org.mitre.oval:tst:123250"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="procmail is earlier than 0:3.22-17.1.2.el5_10" test_ref="oval:org.mitre.oval:tst:123831"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="procmail is earlier than 0:3.22-25.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:123631"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="procmail is earlier than 0:3.22-34.el7_0.1" test_ref="oval:org.mitre.oval:tst:123381"/>
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26451" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1246: nss and nspr security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>nss</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1246-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1246.html"/>
        <reference source="CVE" ref_id="CVE-2013-1740" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1740.html"/>
        <reference source="CVE" ref_id="CVE-2014-1490" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1490.html"/>
        <reference source="CVE" ref_id="CVE-2014-1491" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1491.html"/>
        <reference source="CVE" ref_id="CVE-2014-1492" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1492.html"/>
        <reference source="CVE" ref_id="CVE-2014-1545" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1545.html"/>
        <reference source="CESA-2014:1246" ref_id="CESA-2014:1246" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-September/020634.html"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications.

A flaw was found in the way TLS False Start was implemented in NSS.
An attacker could use this flaw to potentially return unencrypted
information from the server. (CVE-2013-1740)

A race condition was found in the way NSS implemented session ticket
handling as specified by RFC 5077. An attacker could use this flaw to crash
an application using NSS or, in rare cases, execute arbitrary code with the
privileges of the user running that application. (CVE-2014-1490)

It was found that NSS accepted weak Diffie-Hellman Key exchange (DHKE)
parameters. This could possibly lead to weak encryption being used in
communication between the client and the server. (CVE-2014-1491)

An out-of-bounds write flaw was found in NSPR. A remote attacker could
potentially use this flaw to crash an application using NSPR or, possibly,
execute arbitrary code with the privileges of the user running that
application. This NSPR flaw was not exposed to web content in any shipped
version of Firefox. (CVE-2014-1545)

It was found that the implementation of Internationalizing Domain Names in
Applications (IDNA) hostname matching in NSS did not follow the RFC 6125
recommendations. This could lead to certain invalid certificates with
international characters to be accepted as valid. (CVE-2014-1492)

Red Hat would like to thank the Mozilla project for reporting the
CVE-2014-1490, CVE-2014-1491, and CVE-2014-1545 issues. Upstream
acknowledges Brian Smith as the original reporter of CVE-2014-1490, Antoine
Delignat-Lavaud and Karthikeyan Bhargavan as the original reporters of
CVE-2014-1491, and Abhishek Arya as the original reporter of CVE-2014-1545.

The nss and nspr packages have been upgraded to upstream version 3.16.1 and
4.10.6 respectively, which provide a number of bug fixes and enhancements
over the previous versions. (BZ#1110857, BZ#1110860)

This update also fixes the following bugs:

* Previously, when the output.log file was not present on the system, the
shell in the Network Security Services (NSS) specification handled test
failures incorrectly as false positive test results. Consequently, certain
utilities, such as "grep", could not handle failures properly. This update
improves error detection in the specification file, and "grep" and other
utilities now handle missing files or crashes as intended. (BZ#1035281)

* Prior to this update, a subordinate Certificate Authority (CA) of the
ANSSI agency incorrectly issued an intermediate certificate installed on a
network monitoring device. As a consequence, the monitoring device was
enabled to act as an MITM (Man in the Middle) proxy performing traffic
management of domain names or IP addresses that the certificate holder did
not own or control. The trust in the intermediate certificate to issue the
certificate for an MITM device has been revoked, and such a device can no
longer be used for MITM attacks. (BZ#1042684)

* Due to a regression, MD5 certificates were rejected by default because
Network Security Services (NSS) did not trust MD5 certificates. With this
update, MD5 certificates are supported in Red Hat Enterprise Linux 5.
(BZ#11015864)

Users of nss and nspr are advised to upgrade to these updated packages,
which correct these issues and add these enhancements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:10.814-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:30.602-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:01:23.850-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26451 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:55.271-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:08.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="nss-debuginfo is earlier than 0:3.16.1-2.el5" test_ref="oval:org.mitre.oval:tst:138133"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-devel is earlier than 0:3.16.1-2.el5" test_ref="oval:org.mitre.oval:tst:123864"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.1-2.el5" test_ref="oval:org.mitre.oval:tst:123769"/>
            <criterion comment="nss is earlier than 0:3.16.1-2.el5" test_ref="oval:org.mitre.oval:tst:123723"/>
            <criterion comment="nss-tools is earlier than 0:3.16.1-2.el5" test_ref="oval:org.mitre.oval:tst:123383"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26423" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1677 -- wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1677.html" ref_id="RHSA-2014:1677"/>
        <reference source="CESA-2014:1677" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-October/020703.html" ref_id="CESA-2014:1677"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6421" ref_id="CVE-2014-6421"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6422" ref_id="CVE-2014-6422"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6423" ref_id="CVE-2014-6423"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6425" ref_id="CVE-2014-6425"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6428" ref_id="CVE-2014-6428"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6429" ref_id="CVE-2014-6429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6430" ref_id="CVE-2014-6430"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6431" ref_id="CVE-2014-6431"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6432" ref_id="CVE-2014-6432"/>
        <description>Wireshark is a network protocol analyzer. It is used to capture and browse
the traffic running on a computer network.

Multiple flaws were found in Wireshark. If Wireshark read a malformed
packet off a network or opened a malicious dump file, it could crash or,
possibly, execute arbitrary code as the user running Wireshark.
(CVE-2014-6429, CVE-2014-6430, CVE-2014-6431, CVE-2014-6432)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2014-6421, CVE-2014-6422, CVE-2014-6423,
CVE-2014-6425, CVE-2014-6428)

All wireshark users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running instances
of Wireshark must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:14:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:54.743-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:00:30.754-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:19.685-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="wireshark-debuginfo is earlier than 0:1.0.15-7.el5_11" test_ref="oval:org.mitre.oval:tst:125028"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="wireshark-gnome is earlier than 0:1.0.15-7.el5_11" test_ref="oval:org.mitre.oval:tst:125490"/>
            <criterion comment="wireshark is earlier than 0:1.0.15-7.el5_11" test_ref="oval:org.mitre.oval:tst:125413"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26407" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1033: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1033-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1033.html"/>
        <reference source="CVE" ref_id="CVE-2014-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4209.html"/>
        <reference source="CVE" ref_id="CVE-2014-4218" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4218.html"/>
        <reference source="CVE" ref_id="CVE-2014-4219" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4219.html"/>
        <reference source="CVE" ref_id="CVE-2014-4227" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4227.html"/>
        <reference source="CVE" ref_id="CVE-2014-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4244.html"/>
        <reference source="CVE" ref_id="CVE-2014-4252" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4252.html"/>
        <reference source="CVE" ref_id="CVE-2014-4262" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4262.html"/>
        <reference source="CVE" ref_id="CVE-2014-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4263.html"/>
        <reference source="CVE" ref_id="CVE-2014-4265" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4265.html"/>
        <description>IBM Java SE version 6 includes the IBM Java Runtime Environment and the IBM
Java Software Development Kit.

This update fixes several vulnerabilities in the IBM Java Runtime
Environment and the IBM Java Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM Security alerts
page, listed in the References section. (CVE-2014-4209, CVE-2014-4218,
CVE-2014-4219, CVE-2014-4227, CVE-2014-4244, CVE-2014-4252, CVE-2014-4262,
CVE-2014-4263, CVE-2014-4265)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.6.0-ibm are advised to upgrade to these updated
packages, containing the IBM Java SE 6 SR16-FP1 release. All running
instances of IBM Java must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-18T12:09:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-05T14:28:57.508-04:00">DRAFT</status_change>
            <status_change date="2014-09-22T04:00:52.898-04:00">INTERIM</status_change>
            <status_change date="2014-10-13T04:00:35.083-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122517"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122462"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122541"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:121689"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122553"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122398"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122234"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122498"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:121990"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122651"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122357"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122617"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:121901"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122289"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122592"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26388" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1110: glibc security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1110-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1110.html"/>
        <reference source="CESA" ref_id="CESA-2014:1110"/>
        <reference source="CVE" ref_id="CVE-2014-0475" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0475.html"/>
        <reference source="CVE" ref_id="CVE-2014-5119" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-5119.html"/>
        <description>The glibc packages contain the standard C libraries used by multiple
programs on the system. These packages contain the standard C and the
standard math libraries. Without these two libraries, a Linux system cannot
function properly.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-08T16:42:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-17T10:44:08.573-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:35.745-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:00:45.093-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="glibc is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:122956"/>
            <criterion comment="glibc-common is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:122380"/>
            <criterion comment="glibc-devel is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:123024"/>
            <criterion comment="glibc-headers is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:123069"/>
            <criterion comment="glibc-utils is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:122669"/>
            <criterion comment="nscd is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:123071"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="glibc is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:122887"/>
            <criterion comment="glibc-common is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:122739"/>
            <criterion comment="glibc-devel is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:123068"/>
            <criterion comment="glibc-headers is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:123073"/>
            <criterion comment="glibc-static is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:122402"/>
            <criterion comment="glibc-utils is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:122779"/>
            <criterion comment="nscd is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:122909"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="glibc is earlier than 0:2.17-55.el7_0.1" test_ref="oval:org.mitre.oval:tst:123035"/>
            <criterion comment="glibc-common is earlier than 0:2.17-55.el7_0.1" test_ref="oval:org.mitre.oval:tst:122535"/>
            <criterion comment="glibc-devel is earlier than 0:2.17-55.el7_0.1" test_ref="oval:org.mitre.oval:tst:123059"/>
            <criterion comment="glibc-headers is earlier than 0:2.17-55.el7_0.1" test_ref="oval:org.mitre.oval:tst:122432"/>
            <criterion comment="glibc-static is earlier than 0:2.17-55.el7_0.1" test_ref="oval:org.mitre.oval:tst:123014"/>
            <criterion comment="glibc-utils is earlier than 0:2.17-55.el7_0.1" test_ref="oval:org.mitre.oval:tst:122938"/>
            <criterion comment="nscd is earlier than 0:2.17-55.el7_0.1" test_ref="oval:org.mitre.oval:tst:123079"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26375" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1051: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1051-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1051.html"/>
        <reference source="CVE" ref_id="CVE-2014-0538" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0538.html"/>
        <reference source="CVE" ref_id="CVE-2014-0540" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0540.html"/>
        <reference source="CVE" ref_id="CVE-2014-0541" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0541.html"/>
        <reference source="CVE" ref_id="CVE-2014-0542" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0542.html"/>
        <reference source="CVE" ref_id="CVE-2014-0543" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0543.html"/>
        <reference source="CVE" ref_id="CVE-2014-0544" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0544.html"/>
        <reference source="CVE" ref_id="CVE-2014-0545" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0545.html"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed in the Adobe Security Bulletin APSB14-18,
listed in the References section.

Multiple flaws were found in the way flash-plugin displayed certain SWF
content. An attacker could use these flaws to create a specially crafted
SWF file that would cause flash-plugin to crash or, potentially, execute
arbitrary code when the victim loaded a page containing the malicious SWF
content. (CVE-2014-0538, CVE-2014-0540, CVE-2014-0541, CVE-2014-0542, 
CVE-2014-0543, CVE-2014-0544, CVE-2014-0545)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.400.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-18T12:09:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-05T14:28:43.573-04:00">DRAFT</status_change>
            <status_change date="2014-09-22T04:00:50.047-04:00">INTERIM</status_change>
            <status_change date="2014-10-13T04:00:32.651-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.400-1.el5" test_ref="oval:org.mitre.oval:tst:121704"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.400-1.el6" test_ref="oval:org.mitre.oval:tst:122600"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26370" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1036: java-1.5.0-ibm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1036-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1036.html"/>
        <reference source="CVE" ref_id="CVE-2014-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4209.html"/>
        <reference source="CVE" ref_id="CVE-2014-4218" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4218.html"/>
        <reference source="CVE" ref_id="CVE-2014-4219" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4219.html"/>
        <reference source="CVE" ref_id="CVE-2014-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4244.html"/>
        <reference source="CVE" ref_id="CVE-2014-4252" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4252.html"/>
        <reference source="CVE" ref_id="CVE-2014-4262" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4262.html"/>
        <reference source="CVE" ref_id="CVE-2014-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4263.html"/>
        <description>IBM J2SE version 5.0 includes the IBM Java Runtime Environment and the IBM
Java Software Development Kit.

This update fixes several vulnerabilities in the IBM Java Runtime
Environment and the IBM Java Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM Security alerts
page, listed in the References section. (CVE-2014-4209, CVE-2014-4218,
CVE-2014-4219, CVE-2014-4244, CVE-2014-4252, CVE-2014-4262, CVE-2014-4263)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.5.0-ibm are advised to upgrade to these updated
packages, containing the IBM J2SE 5.0 SR16-FP7 release. All running
instances of IBM Java must be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-18T12:09:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-05T14:28:47.103-04:00">DRAFT</status_change>
            <status_change date="2014-09-22T04:00:49.235-04:00">INTERIM</status_change>
            <status_change date="2014-10-13T04:00:31.718-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122123"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122509"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122656"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122192"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:121907"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122671"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122596"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122687"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122607"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:121790"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122552"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122629"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122566"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122347"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122275"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26315" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1053: openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1053-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1053.html"/>
        <reference source="CESA" ref_id="CESA-2014:1053"/>
        <reference source="CVE" ref_id="CVE-2014-0221" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0221.html"/>
        <reference source="CVE" ref_id="CVE-2014-3505" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3505.html"/>
        <reference source="CVE" ref_id="CVE-2014-3506" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3506.html"/>
        <reference source="CVE" ref_id="CVE-2014-3508" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3508.html"/>
        <reference source="CVE" ref_id="CVE-2014-3510" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3510.html"/>
        <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL),
Transport Layer Security (TLS), and Datagram Transport Layer Security
(DTLS) protocols, as well as a full-strength, general purpose cryptography
library.

It was discovered that the OBJ_obj2txt() function could fail to properly
NUL-terminate its output. This could possibly cause an application using
OpenSSL functions to format fields of X.509 certificates to disclose
portions of its memory. (CVE-2014-3508)

Multiple flaws were discovered in the way OpenSSL handled DTLS packets.
A remote attacker could use these flaws to cause a DTLS server or client
using OpenSSL to crash or use excessive amounts of memory. (CVE-2014-0221,
CVE-2014-3505, CVE-2014-3506)

A NULL pointer dereference flaw was found in the way OpenSSL performed a
handshake when using the anonymous Diffie-Hellman (DH) key exchange. A
malicious server could cause a DTLS client using OpenSSL to crash if that
client had anonymous DH cipher suites enabled. (CVE-2014-3510)

Red Hat would like to thank the OpenSSL project for reporting
CVE-2014-0221. Upstream acknowledges Imre Rad of Search-Lab as the original
reporter of this issue.

All OpenSSL users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-18T12:09:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-05T14:28:41.719-04:00">DRAFT</status_change>
            <status_change date="2014-09-22T04:00:45.590-04:00">INTERIM</status_change>
            <status_change date="2014-10-13T04:00:28.682-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openssl is earlier than 0:0.9.8e-27.el5_10.4" test_ref="oval:org.mitre.oval:tst:122697"/>
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-27.el5_10.4" test_ref="oval:org.mitre.oval:tst:122208"/>
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-27.el5_10.4" test_ref="oval:org.mitre.oval:tst:122582"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26314" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1012: php53 and php security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1012-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1012.html"/>
        <reference source="CESA" ref_id="CESA-2014:1012"/>
        <reference source="CVE" ref_id="CVE-2012-1571" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1571.html"/>
        <reference source="CVE" ref_id="CVE-2013-6712" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6712.html"/>
        <reference source="CVE" ref_id="CVE-2014-0237" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0237.html"/>
        <reference source="CVE" ref_id="CVE-2014-0238" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0238.html"/>
        <reference source="CVE" ref_id="CVE-2014-1943" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1943.html"/>
        <reference source="CVE" ref_id="CVE-2014-2270" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2270.html"/>
        <reference source="CVE" ref_id="CVE-2014-3479" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3479.html"/>
        <reference source="CVE" ref_id="CVE-2014-3480" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3480.html"/>
        <reference source="CVE" ref_id="CVE-2014-3515" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3515.html"/>
        <reference source="CVE" ref_id="CVE-2014-4049" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4049.html"/>
        <reference source="CVE" ref_id="CVE-2014-4721" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4721.html"/>
        <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server. PHP's fileinfo module provides functions used to identify a
particular file according to the type of data contained by the file.

Multiple denial of service flaws were found in the way the File Information
(fileinfo) extension parsed certain Composite Document Format (CDF) files.
A remote attacker could use either of these flaws to crash a PHP
application using fileinfo via a specially crafted CDF file.
(CVE-2014-0237, CVE-2014-0238, CVE-2014-3479, CVE-2014-3480, CVE-2012-1571)

Two denial of service flaws were found in the way the File Information
(fileinfo) extension handled indirect and search rules. A remote attacker
could use either of these flaws to cause a PHP application using fileinfo
to crash or consume an excessive amount of CPU. (CVE-2014-1943,
CVE-2014-2270)

A heap-based buffer overflow flaw was found in the way PHP parsed DNS TXT
records. A malicious DNS server or a man-in-the-middle attacker could
possibly use this flaw to execute arbitrary code as the PHP interpreter if
a PHP application used the dns_get_record() function to perform a DNS
query. (CVE-2014-4049)

A type confusion issue was found in PHP's phpinfo() function. A malicious
script author could possibly use this flaw to disclose certain portions of
server memory. (CVE-2014-4721)

A buffer over-read flaw was found in the way the DateInterval class parsed
interval specifications. An attacker able to make a PHP application parse a
specially crafted specification using DateInterval could possibly cause the
PHP interpreter to crash. (CVE-2013-6712)

A type confusion issue was found in the SPL ArrayObject and
SPLObjectStorage classes' unserialize() method. A remote attacker able to
submit specially crafted input to a PHP application, which would then
unserialize this input using one of the aforementioned methods, could use
this flaw to execute arbitrary code with the privileges of the user running
that PHP application. (CVE-2014-3515)

The CVE-2014-0237, CVE-2014-0238, CVE-2014-3479, and CVE-2014-3480 issues
were discovered by Francisco Alonso of Red Hat Product Security.

All php53 and php users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-18T12:09:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-05T14:28:51.902-04:00">DRAFT</status_change>
            <status_change date="2014-09-22T04:00:44.886-04:00">INTERIM</status_change>
            <status_change date="2014-10-13T04:00:27.250-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php53 is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:121848"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122422"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:121506"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122213"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122442"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122364"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122385"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122085"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122300"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122383"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122205"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122090"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122243"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:121820"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122302"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122386"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:121844"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122063"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:121863"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122138"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:121502"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122144"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122521"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122240"/>
            <criterion comment="php-common is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122396"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122067"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122020"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:121691"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122483"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122529"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:121529"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122491"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122469"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122293"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122353"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:121951"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122239"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:121534"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122478"/>
            <criterion comment="php-process is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122446"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122000"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122382"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122231"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122423"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:121548"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122450"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122373"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122355"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26186" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1004: yum-updatesd security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>yum-updatesd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1004-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1004.html"/>
        <reference source="CVE" ref_id="CVE-2014-0022" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0022.html"/>
        <reference source="CESA-2014:1004" ref_id="CESA-2014:1004" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-August/020462.html"/>
        <description>The yum-updatesd package provides a daemon which checks for available
updates and can notify you when they are available via email, syslog,
or dbus.

It was discovered that yum-updatesd did not properly perform RPM package
signature checks. When yum-updatesd was configured to automatically install
updates, a remote attacker could use this flaw to install a malicious
update on the target system using an unsigned RPM or an RPM signed with an
untrusted key. (CVE-2014-0022)

All yum-updatesd users are advised to upgrade to this updated package,
which contains a backported patch to correct this issue. After installing
this update, the yum-updatesd service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-05T10:24:53">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-08-07T15:02:33.673-04:00">DRAFT</status_change>
            <status_change date="2014-08-25T04:01:35.850-04:00">INTERIM</status_change>
            <status_change date="2014-09-15T04:00:43.432-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26186 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:50.743-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:08.111-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="yum-updatesd is earlier than 1:0.9-6.el5_10" test_ref="oval:org.mitre.oval:tst:121478"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26042" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1041: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1041-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1041.html"/>
        <reference source="CVE" ref_id="CVE-2014-4208" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4208.html"/>
        <reference source="CVE" ref_id="CVE-2014-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4209.html"/>
        <reference source="CVE" ref_id="CVE-2014-4218" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4218.html"/>
        <reference source="CVE" ref_id="CVE-2014-4219" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4219.html"/>
        <reference source="CVE" ref_id="CVE-2014-4220" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4220.html"/>
        <reference source="CVE" ref_id="CVE-2014-4221" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4221.html"/>
        <reference source="CVE" ref_id="CVE-2014-4227" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4227.html"/>
        <reference source="CVE" ref_id="CVE-2014-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4244.html"/>
        <reference source="CVE" ref_id="CVE-2014-4252" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4252.html"/>
        <reference source="CVE" ref_id="CVE-2014-4262" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4262.html"/>
        <reference source="CVE" ref_id="CVE-2014-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4263.html"/>
        <reference source="CVE" ref_id="CVE-2014-4265" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4265.html"/>
        <reference source="CVE" ref_id="CVE-2014-4266" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4266.html"/>
        <description>IBM Java SE version 7 includes the IBM Java Runtime Environment and the IBM
Java Software Development Kit.

This update fixes several vulnerabilities in the IBM Java Runtime
Environment and the IBM Java Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM Security alerts
page, listed in the References section. (CVE-2014-4208, CVE-2014-4209,
CVE-2014-4218, CVE-2014-4219, CVE-2014-4220, CVE-2014-4221, CVE-2014-4227,
CVE-2014-4244, CVE-2014-4252, CVE-2014-4262, CVE-2014-4263, CVE-2014-4265,
CVE-2014-4266)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.7.0-ibm are advised to upgrade to these updated
packages, containing the IBM Java SE 7 SR7-FP1 release. All running
instances of IBM Java must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-18T12:09:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-05T14:28:56.428-04:00">DRAFT</status_change>
            <status_change date="2014-09-22T04:00:36.889-04:00">INTERIM</status_change>
            <status_change date="2014-10-13T04:00:19.105-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122406"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122155"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122424"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122504"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122622"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122508"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122134"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122122"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122662"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122550"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122312"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122672"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26030" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1244: bind97 security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1244-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1244.html"/>
        <reference source="CVE" ref_id="CVE-2014-0591" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0591.html"/>
        <reference source="CESA-2014:1244" ref_id="CESA-2014:1244" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-September/020608.html"/>
        <description>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. It contains a DNS server (named), a resolver
library with routines for applications to use when interfacing with DNS,
and tools for verifying that the DNS server is operating correctly.
These packages contain version 9.7 of the BIND suite.

A denial of service flaw was found in the way BIND handled queries for
NSEC3-signed zones. A remote attacker could use this flaw against an
authoritative name server that served NCES3-signed zones by sending a
specially crafted query, which, when processed, would cause named to crash.
(CVE-2014-0591)

Note: The CVE-2014-0591 issue does not directly affect the version of
bind97 shipped in Red Hat Enterprise Linux 5. This issue is being addressed
however to assure it is not introduced in future builds of bind97 (possibly
built with a different compiler or C library optimization).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:03.669-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:18.298-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:01:16.201-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26030 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:50.065-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:07.739-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind97 is earlier than 32:9.7.0-21.P2.el5" test_ref="oval:org.mitre.oval:tst:123907"/>
            <criterion comment="bind97-chroot is earlier than 32:9.7.0-21.P2.el5" test_ref="oval:org.mitre.oval:tst:123810"/>
            <criterion comment="bind97-devel is earlier than 32:9.7.0-21.P2.el5" test_ref="oval:org.mitre.oval:tst:123370"/>
            <criterion comment="bind97-libs is earlier than 32:9.7.0-21.P2.el5" test_ref="oval:org.mitre.oval:tst:123726"/>
            <criterion comment="bind97-utils is earlier than 32:9.7.0-21.P2.el5" test_ref="oval:org.mitre.oval:tst:123862"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="bind97-debuginfo is earlier than 32:9.7.0-21.P2.el5" test_ref="oval:org.mitre.oval:tst:138426"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25428" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0908: java-1.6.0-sun security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0908-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0908.html"/>
        <reference source="CVE" ref_id="CVE-2014-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4209.html"/>
        <reference source="CVE" ref_id="CVE-2014-4216" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4216.html"/>
        <reference source="CVE" ref_id="CVE-2014-4218" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4218.html"/>
        <reference source="CVE" ref_id="CVE-2014-4219" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4219.html"/>
        <reference source="CVE" ref_id="CVE-2014-4227" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4227.html"/>
        <reference source="CVE" ref_id="CVE-2014-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4244.html"/>
        <reference source="CVE" ref_id="CVE-2014-4252" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4252.html"/>
        <reference source="CVE" ref_id="CVE-2014-4262" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4262.html"/>
        <reference source="CVE" ref_id="CVE-2014-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4263.html"/>
        <reference source="CVE" ref_id="CVE-2014-4265" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4265.html"/>
        <description>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch page, listed in the References section. (CVE-2014-4219,
CVE-2014-4216, CVE-2014-4262, CVE-2014-4209, CVE-2014-4218,
CVE-2014-4252, CVE-2014-4244, CVE-2014-4263, CVE-2014-4227,
CVE-2014-4265)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

Note: The way in which the Oracle Java SE packages are delivered has
changed. They now reside in a separate channel/repository that requires
action from the user to perform prior to getting updated packages.
For information on subscribing to the new channel/repository please refer
to: https://access.redhat.com/solutions/732883

All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide Oracle Java 6 Update 81 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:00:47.528-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:04:17.819-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:02:19.490-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.81-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115505"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.81-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:116062"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.81-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115401"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.81-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:116084"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.81-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:116089"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.81-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115789"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.81-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:116078"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.81-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115370"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.81-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:116305"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.81-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115363"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.81-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115315"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.81-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115322"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25379" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0920: httpd security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0920-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0920.html"/>
        <reference source="CESA" ref_id="CESA-2014:0920"/>
        <reference source="CVE" ref_id="CVE-2014-0118" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0118.html"/>
        <reference source="CVE" ref_id="CVE-2014-0226" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0226.html"/>
        <reference source="CVE" ref_id="CVE-2014-0231" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0231.html"/>
        <description>The httpd packages provide the Apache HTTP Server, a powerful, efficient,
and extensible web server.

A race condition flaw, leading to heap-based buffer overflows, was found in
the mod_status httpd module. A remote attacker able to access a status page
served by mod_status on a server using a threaded Multi-Processing Module
(MPM) could send a specially crafted request that would cause the httpd
child process to crash or, possibly, allow the attacker to execute
arbitrary code with the privileges of the "apache" user. (CVE-2014-0226)

A denial of service flaw was found in the way httpd's mod_deflate module
handled request body decompression (configured via the "DEFLATE" input
filter). A remote attacker able to send a request whose body would be
decompressed could use this flaw to consume an excessive amount of system
memory and CPU on the target system. (CVE-2014-0118)

A denial of service flaw was found in the way httpd's mod_cgid module
executed CGI scripts that did not read data from the standard input.
A remote attacker could submit a specially crafted request that would cause
the httpd child process to hang indefinitely. (CVE-2014-0231)

All httpd users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:01:11.071-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:04:06.499-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:02:07.085-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd is earlier than 0:2.2.3-87.el5_10" test_ref="oval:org.mitre.oval:tst:116175"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-87.el5_10" test_ref="oval:org.mitre.oval:tst:116210"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-87.el5_10" test_ref="oval:org.mitre.oval:tst:116201"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.3-87.el5_10" test_ref="oval:org.mitre.oval:tst:116271"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd is earlier than 0:2.2.3-87.el5.centos" test_ref="oval:org.mitre.oval:tst:115938"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-87.el5.centos" test_ref="oval:org.mitre.oval:tst:115372"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-87.el5.centos" test_ref="oval:org.mitre.oval:tst:116114"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.3-87.el5.centos" test_ref="oval:org.mitre.oval:tst:116196"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd is earlier than 0:2.2.15-31.el6_5" test_ref="oval:org.mitre.oval:tst:115650"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.15-31.el6_5" test_ref="oval:org.mitre.oval:tst:116136"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-31.el6_5" test_ref="oval:org.mitre.oval:tst:115382"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-31.el6_5" test_ref="oval:org.mitre.oval:tst:116334"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.15-31.el6_5" test_ref="oval:org.mitre.oval:tst:116330"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd is earlier than 0:2.2.15-31.el6.centos" test_ref="oval:org.mitre.oval:tst:116217"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.15-31.el6.centos" test_ref="oval:org.mitre.oval:tst:116354"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-31.el6.centos" test_ref="oval:org.mitre.oval:tst:116323"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-31.el6.centos" test_ref="oval:org.mitre.oval:tst:115768"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.15-31.el6.centos" test_ref="oval:org.mitre.oval:tst:116289"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25358" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0907: java-1.6.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0907-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0907.html"/>
        <reference source="CESA" ref_id="CESA-2014:0907"/>
        <reference source="CVE" ref_id="CVE-2014-2490" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2490.html"/>
        <reference source="CVE" ref_id="CVE-2014-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4209.html"/>
        <reference source="CVE" ref_id="CVE-2014-4216" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4216.html"/>
        <reference source="CVE" ref_id="CVE-2014-4218" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4218.html"/>
        <reference source="CVE" ref_id="CVE-2014-4219" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4219.html"/>
        <reference source="CVE" ref_id="CVE-2014-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4244.html"/>
        <reference source="CVE" ref_id="CVE-2014-4252" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4252.html"/>
        <reference source="CVE" ref_id="CVE-2014-4262" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4262.html"/>
        <reference source="CVE" ref_id="CVE-2014-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4263.html"/>
        <reference source="CVE" ref_id="CVE-2014-4266" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4266.html"/>
        <description>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.

It was discovered that the Hotspot component in OpenJDK did not properly
verify bytecode from the class files. An untrusted Java application or
applet could possibly use these flaws to bypass Java sandbox restrictions.
(CVE-2014-4216, CVE-2014-4219)

A format string flaw was discovered in the Hotspot component event logger
in OpenJDK. An untrusted Java application or applet could use this flaw to
crash the Java Virtual Machine or, potentially, execute arbitrary code with
the privileges of the Java Virtual Machine. (CVE-2014-2490)

An improper permission check issue was discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
this flaw to bypass Java sandbox restrictions. (CVE-2014-4262)

Multiple flaws were discovered in the JMX, Libraries, Security, and
Serviceability components in OpenJDK. An untrusted Java application or
applet could use these flaws to bypass certain Java sandbox restrictions.
(CVE-2014-4209, CVE-2014-4218, CVE-2014-4252, CVE-2014-4266)

It was discovered that the RSA algorithm in the Security component in
OpenJDK did not sufficiently perform blinding while performing operations
that were using private keys. An attacker able to measure timing
differences of those operations could possibly leak information about the
used keys. (CVE-2014-4244)

The Diffie-Hellman (DH) key exchange algorithm implementation in the
Security component in OpenJDK failed to validate public DH parameters
properly. This could cause OpenJDK to accept and use weak parameters,
allowing an attacker to recover the negotiated key. (CVE-2014-4263)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

This update also fixes the following bug:

* Prior to this update, an application accessing an unsynchronized HashMap
could potentially enter an infinite loop and consume an excessive amount of
CPU resources. This update resolves this issue. (BZ#1115580)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:00:55.436-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:04:02.852-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:02:03.110-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-6.1.13.4.el5_10" test_ref="oval:org.mitre.oval:tst:116193"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-6.1.13.4.el5_10" test_ref="oval:org.mitre.oval:tst:115888"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-6.1.13.4.el5_10" test_ref="oval:org.mitre.oval:tst:116093"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-6.1.13.4.el5_10" test_ref="oval:org.mitre.oval:tst:116146"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-6.1.13.4.el5_10" test_ref="oval:org.mitre.oval:tst:116148"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:116179"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:116211"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:116107"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:116029"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:116192"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:116140"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:116166"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:115881"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:115700"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:115804"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25335" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0916: nss and nspr security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 7</platform>
          <product>nspr</product>
          <product>nss</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0916-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0916.html"/>
        <reference source="CESA" ref_id="CESA-2014:0916"/>
        <reference source="CVE" ref_id="CVE-2014-1544" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1544.html"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

A race condition was found in the way NSS verified certain certificates.
A remote attacker could use this flaw to crash an application using NSS or,
possibly, execute arbitrary code with the privileges of the user running
that application. (CVE-2014-1544)

Red Hat would like to thank the Mozilla project for reporting
CVE-2014-1544. Upstream acknowledges Tyson Smith and Jesse Schwartzentruber
as the original reporters.

Users of NSS and NSPR are advised to upgrade to these updated packages,
which correct this issue. After installing this update, applications using
NSS or NSPR must be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:01:04.458-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:03:57.995-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:01:57.105-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="nss is earlier than 0:3.15.3-7.el5_10" test_ref="oval:org.mitre.oval:tst:115983"/>
            <criterion comment="nss-devel is earlier than 0:3.15.3-7.el5_10" test_ref="oval:org.mitre.oval:tst:116285"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-7.el5_10" test_ref="oval:org.mitre.oval:tst:115635"/>
            <criterion comment="nss-tools is earlier than 0:3.15.3-7.el5_10" test_ref="oval:org.mitre.oval:tst:115735"/>
            <criterion comment="nspr is earlier than 0:4.10.6-1.el5_10" test_ref="oval:org.mitre.oval:tst:115855"/>
            <criterion comment="nspr-devel is earlier than 0:4.10.6-1.el5_10" test_ref="oval:org.mitre.oval:tst:116024"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="nss is earlier than 0:3.15.4-7.el7_0" test_ref="oval:org.mitre.oval:tst:116165"/>
            <criterion comment="nss-devel is earlier than 0:3.15.4-7.el7_0" test_ref="oval:org.mitre.oval:tst:116056"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.4-7.el7_0" test_ref="oval:org.mitre.oval:tst:115928"/>
            <criterion comment="nss-sysinit is earlier than 0:3.15.4-7.el7_0" test_ref="oval:org.mitre.oval:tst:116149"/>
            <criterion comment="nss-tools is earlier than 0:3.15.4-7.el7_0" test_ref="oval:org.mitre.oval:tst:116219"/>
            <criterion comment="nspr is earlier than 0:4.10.6-1.el7_0" test_ref="oval:org.mitre.oval:tst:116012"/>
            <criterion comment="nspr-devel is earlier than 0:4.10.6-1.el7_0" test_ref="oval:org.mitre.oval:tst:116306"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25312" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0902: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0902-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0902.html"/>
        <reference source="CVE" ref_id="CVE-2014-2483" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2483.html"/>
        <reference source="CVE" ref_id="CVE-2014-2490" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2490.html"/>
        <reference source="CVE" ref_id="CVE-2014-4208" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4208.html"/>
        <reference source="CVE" ref_id="CVE-2014-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4209.html"/>
        <reference source="CVE" ref_id="CVE-2014-4216" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4216.html"/>
        <reference source="CVE" ref_id="CVE-2014-4218" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4218.html"/>
        <reference source="CVE" ref_id="CVE-2014-4219" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4219.html"/>
        <reference source="CVE" ref_id="CVE-2014-4220" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4220.html"/>
        <reference source="CVE" ref_id="CVE-2014-4221" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4221.html"/>
        <reference source="CVE" ref_id="CVE-2014-4223" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4223.html"/>
        <reference source="CVE" ref_id="CVE-2014-4227" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4227.html"/>
        <reference source="CVE" ref_id="CVE-2014-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4244.html"/>
        <reference source="CVE" ref_id="CVE-2014-4252" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4252.html"/>
        <reference source="CVE" ref_id="CVE-2014-4262" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4262.html"/>
        <reference source="CVE" ref_id="CVE-2014-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4263.html"/>
        <reference source="CVE" ref_id="CVE-2014-4264" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4264.html"/>
        <reference source="CVE" ref_id="CVE-2014-4265" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4265.html"/>
        <reference source="CVE" ref_id="CVE-2014-4266" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4266.html"/>
        <description>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2014-4219, CVE-2014-2490, CVE-2014-4216, CVE-2014-4223, CVE-2014-4262,
CVE-2014-2483, CVE-2014-4209, CVE-2014-4218, CVE-2014-4252, CVE-2014-4266,
CVE-2014-4221, CVE-2014-4244, CVE-2014-4263, CVE-2014-4227, CVE-2014-4265,
CVE-2014-4220, CVE-2014-4208, CVE-2014-4264)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

Note: The way in which the Oracle Java SE packages are delivered has
changed. They now reside in a separate channel/repository that requires
action from the user to perform prior to getting updated packages.
For information on subscribing to the new channel/repository please refer
to: https://access.redhat.com/solutions/732883

All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 65 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:01:24.874-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:03:51.600-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:01:47.239-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.65-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:116159"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.65-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:115925"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.65-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:115810"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.65-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:115721"/>
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.65-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:115380"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.65-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:115708"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.65-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:116208"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.65-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115996"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.65-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115979"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.65-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:116130"/>
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.65-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:116045"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.65-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:116028"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25271" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0866: samba and samba3x security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0866-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0866.html"/>
        <reference source="CESA" ref_id="CESA-2014:0866"/>
        <reference source="CVE" ref_id="CVE-2014-0244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0244.html"/>
        <reference source="CVE" ref_id="CVE-2014-3493" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3493.html"/>
        <description>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

A denial of service flaw was found in the way the sys_recvfile() function
of nmbd, the NetBIOS message block daemon, processed non-blocking sockets.
An attacker could send a specially crafted packet that, when processed,
would cause nmbd to enter an infinite loop and consume an excessive amount
of CPU time. (CVE-2014-0244)

It was discovered that smbd, the Samba file server daemon, did not properly
handle certain files that were stored on the disk and used a valid Unicode
character in the file name. An attacker able to send an authenticated
non-Unicode request that attempted to read such a file could cause smbd to
crash. (CVE-2014-3493)

Red Hat would like to thank Daniel Berteaud of FIREWALL-SERVICES SARL for
reporting CVE-2014-0244, and the Samba project for reporting CVE-2014-3493.
The Samba project acknowledges Simon Arlott as the original reporter of
CVE-2014-3493.

All Samba users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-21T11:31:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-25T11:59:58.068-04:00">DRAFT</status_change>
            <status_change date="2014-08-11T04:01:03.078-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:07.457-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115866"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115752"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115828"/>
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115827"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115213"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115671"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115545"/>
            <criterion comment="samba3x is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115293"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115904"/>
            <criterion comment="samba is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115588"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115108"/>
            <criterion comment="samba-swat is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115089"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115719"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115699"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115908"/>
            <criterion comment="samba-common is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115002"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115794"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115854"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115998"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25270" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0919: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0919-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0919.html"/>
        <reference source="CESA" ref_id="CESA-2014:0919"/>
        <reference source="CVE" ref_id="CVE-2014-1547" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1547.html"/>
        <reference source="CVE" ref_id="CVE-2014-1555" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1555.html"/>
        <reference source="CVE" ref_id="CVE-2014-1556" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1556.html"/>
        <reference source="CVE" ref_id="CVE-2014-1557" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1557.html"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1547, CVE-2014-1555, CVE-2014-1556, CVE-2014-1557)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Christian Holler, David Keeler, Byron Campen, Jethro
Beekman, Patrick Cozzi, and Mozilla community member John as the original
reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.7.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 24.7.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:00:58.850-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:03:41.731-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:01:31.561-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:24.7.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:116099"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:24.7.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:116303"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="firefox is earlier than 0:24.7.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:116256"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="firefox is earlier than 0:24.7.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:116333"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 7 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:24.7.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:116085"/>
            <criterion comment="xulrunner is earlier than 0:24.7.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:115740"/>
            <criterion comment="xulrunner-devel is earlier than 0:24.7.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:115371"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 7 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:24.7.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:116167"/>
            <criterion comment="xulrunner is earlier than 0:24.7.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:115784"/>
            <criterion comment="xulrunner-devel is earlier than 0:24.7.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:115931"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25266" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0926: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0926-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0926.html"/>
        <reference source="CESA" ref_id="CESA-2014:0926"/>
        <reference source="CVE" ref_id="CVE-2014-2678" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2678.html"/>
        <reference source="CVE" ref_id="CVE-2014-4021" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4021.html"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A NULL pointer dereference flaw was found in the rds_iw_laddr_check()
function in the Linux kernel's implementation of Reliable Datagram Sockets
(RDS). A local, unprivileged user could use this flaw to crash the system.
(CVE-2014-2678, Moderate)

* It was found that the Xen hypervisor implementation did not properly
clean memory pages previously allocated by the hypervisor. A privileged
guest user could potentially use this flaw to read data relating to other
guests or the hypervisor itself. (CVE-2014-4021, Moderate)

Red Hat would like to thank the Xen project for reporting CVE-2014-4021.
Upstream acknowledges Jan Beulich as the original reporter.

This update also fixes the following bugs:

* A bug in the journaling block device (jbd and jbd2) code could, under
certain circumstances, trigger a BUG_ON() assertion and result in a kernel
oops. This happened when an application performed an extensive number of
commits to the journal of the ext3 file system and there was no currently
active transaction while synchronizing the file's in-core state. This
problem has been resolved by correcting respective test conditions in the
jbd and jbd2 code. (BZ#1097528)

* After a statically defined gateway became unreachable and its
corresponding neighbor entry entered a FAILED state, the gateway stayed in
the FAILED state even after it became reachable again. As a consequence,
traffic was not routed through that gateway. This update allows probing
such a gateway automatically so that the traffic can be routed through
this gateway again once it becomes reachable. (BZ#1106354)

* Due to an incorrect condition check in the IPv6 code, the ipv6 driver
was unable to correctly assemble incoming packet fragments, which resulted
in a high IPv6 packet loss rate. This update fixes the said check for a
fragment overlap and ensures that incoming IPv6 packet fragments are now
processed as expected. (BZ#1107932)

* Recent changes in the d_splice_alias() function introduced a bug that
allowed d_splice_alias() to return a dentry from a different directory
than the directory being looked up. As a consequence in cluster
environment, a kernel panic could be triggered when a directory was being
removed while a concurrent cross-directory operation was performed on this
directory on another cluster node. This update avoids the kernel panic in
this situation by correcting the search logic in the d_splice_alias()
function so that the function can no longer return a dentry from an
incorrect directory. (BZ#1109720)

* The NFSv4 server did not handle multiple OPEN operations to the same file
separately, which could cause the NFSv4 client to repeatedly send CLOSE
requests with the same state ID, even though the NFS server rejected the
request with an NFS4ERR_OLD_STATEID (10024) error code. This update
ensures that the NFSv4 client no longer re-sends the same CLOSE request
after receiving NFS4ERR_OLD_STATEID. (BZ#1113468)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:01:18.462-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:03:41.098-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:01:30.880-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:116341"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:116067"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:116356"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:116342"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:115950"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:116063"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:116015"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:116021"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:116237"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:115984"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:116367"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:116104"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25249" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0890: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0890-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0890.html"/>
        <reference source="CESA" ref_id="CESA-2014:0890"/>
        <reference source="CVE" ref_id="CVE-2014-2483" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2483.html"/>
        <reference source="CVE" ref_id="CVE-2014-2490" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2490.html"/>
        <reference source="CVE" ref_id="CVE-2014-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4209.html"/>
        <reference source="CVE" ref_id="CVE-2014-4216" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4216.html"/>
        <reference source="CVE" ref_id="CVE-2014-4218" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4218.html"/>
        <reference source="CVE" ref_id="CVE-2014-4219" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4219.html"/>
        <reference source="CVE" ref_id="CVE-2014-4221" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4221.html"/>
        <reference source="CVE" ref_id="CVE-2014-4223" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4223.html"/>
        <reference source="CVE" ref_id="CVE-2014-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4244.html"/>
        <reference source="CVE" ref_id="CVE-2014-4252" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4252.html"/>
        <reference source="CVE" ref_id="CVE-2014-4262" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4262.html"/>
        <reference source="CVE" ref_id="CVE-2014-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4263.html"/>
        <reference source="CVE" ref_id="CVE-2014-4266" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4266.html"/>
        <description>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

It was discovered that the Hotspot component in OpenJDK did not properly
verify bytecode from the class files. An untrusted Java application or
applet could possibly use these flaws to bypass Java sandbox restrictions.
(CVE-2014-4216, CVE-2014-4219)

A format string flaw was discovered in the Hotspot component event logger
in OpenJDK. An untrusted Java application or applet could use this flaw to
crash the Java Virtual Machine or, potentially, execute arbitrary code with
the privileges of the Java Virtual Machine. (CVE-2014-2490)

Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-4223,
CVE-2014-4262, CVE-2014-2483)

Multiple flaws were discovered in the JMX, Libraries, Security, and
Serviceability components in OpenJDK. An untrusted Java application or
applet could use these flaws to bypass certain Java sandbox restrictions.
(CVE-2014-4209, CVE-2014-4218, CVE-2014-4221, CVE-2014-4252, CVE-2014-4266)

It was discovered that the RSA algorithm in the Security component in
OpenJDK did not sufficiently perform blinding while performing operations
that were using private keys. An attacker able to measure timing
differences of those operations could possibly leak information about the
used keys. (CVE-2014-4244)

The Diffie-Hellman (DH) key exchange algorithm implementation in the
Security component in OpenJDK failed to validate public DH parameters
properly. This could cause OpenJDK to accept and use weak parameters,
allowing an attacker to recover the negotiated key. (CVE-2014-4263)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-21T11:31:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-25T12:00:00.850-04:00">DRAFT</status_change>
            <status_change date="2014-08-11T04:01:01.820-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:06.398-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.65-2.5.1.2.el5_10" test_ref="oval:org.mitre.oval:tst:115975"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.65-2.5.1.2.el5_10" test_ref="oval:org.mitre.oval:tst:116040"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.65-2.5.1.2.el5_10" test_ref="oval:org.mitre.oval:tst:115056"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.65-2.5.1.2.el5_10" test_ref="oval:org.mitre.oval:tst:115402"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.65-2.5.1.2.el5_10" test_ref="oval:org.mitre.oval:tst:115857"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25210" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0860: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0860-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0860.html"/>
        <reference source="CVE" ref_id="CVE-2014-0537" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0537.html"/>
        <reference source="CVE" ref_id="CVE-2014-0539" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0539.html"/>
        <reference source="CVE" ref_id="CVE-2014-4671" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4671.html"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed in the Adobe Security Bulletin APSB14-17,
listed in the References section.

Multiple flaws were found in the way flash-plugin displayed certain SWF
content. An attacker could use these flaws to create a specially crafted
SWF file that would cause flash-plugin to crash or, potentially, execute
arbitrary code when the victim loaded a page containing the malicious SWF
content. (CVE-2014-0537, CVE-2014-0539)

This update also fixes a flaw that would lead to Cross-Site Request Forgery
(CSRF) attacks. (CVE-2014-4671)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.394.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:01:12.002-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:03:29.634-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:01:15.422-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.394-1.el5" test_ref="oval:org.mitre.oval:tst:116002"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.394-1.el6" test_ref="oval:org.mitre.oval:tst:116066"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25062" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: RHSA-2014:0866: samba and samba3x security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0866-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0866.html"/>
        <reference source="CESA" ref_id="CESA-2014:0866"/>
        <reference source="CVE" ref_id="CVE-2014-0244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0244.html"/>
        <reference source="CVE" ref_id="CVE-2014-3493" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3493.html"/>
        <description>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

A denial of service flaw was found in the way the sys_recvfile() function
of nmbd, the NetBIOS message block daemon, processed non-blocking sockets.
An attacker could send a specially crafted packet that, when processed,
would cause nmbd to enter an infinite loop and consume an excessive amount
of CPU time. (CVE-2014-0244)

It was discovered that smbd, the Samba file server daemon, did not properly
handle certain files that were stored on the disk and used a valid Unicode
character in the file name. An attacker able to send an authenticated
non-Unicode request that attempted to read such a file could cause smbd to
crash. (CVE-2014-3493)

Red Hat would like to thank Daniel Berteaud of FIREWALL-SERVICES SARL for
reporting CVE-2014-0244, and the Samba project for reporting CVE-2014-3493.
The Samba project acknowledges Simon Arlott as the original reporter of
CVE-2014-3493.

All Samba users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:01:02.654-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:03:09.301-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:00:51.397-04:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-11T18:27:00.643-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-11T18:27:00.643-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:116253"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115374"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115965"/>
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:116259"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115686"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:116076"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:116190"/>
            <criterion comment="samba3x is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115479"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:116200"/>
            <criterion comment="samba is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:116223"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115954"/>
            <criterion comment="samba-swat is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:116106"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115675"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:116097"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115887"/>
            <criterion comment="samba-common is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115270"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:116003"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115986"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115949"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:116128"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24964" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: RHSA-2014:0890: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0890-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0890.html"/>
        <reference source="CESA" ref_id="CESA-2014:0890"/>
        <reference source="CVE" ref_id="CVE-2014-2483" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2483.html"/>
        <reference source="CVE" ref_id="CVE-2014-2490" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2490.html"/>
        <reference source="CVE" ref_id="CVE-2014-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4209.html"/>
        <reference source="CVE" ref_id="CVE-2014-4216" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4216.html"/>
        <reference source="CVE" ref_id="CVE-2014-4218" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4218.html"/>
        <reference source="CVE" ref_id="CVE-2014-4219" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4219.html"/>
        <reference source="CVE" ref_id="CVE-2014-4221" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4221.html"/>
        <reference source="CVE" ref_id="CVE-2014-4223" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4223.html"/>
        <reference source="CVE" ref_id="CVE-2014-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4244.html"/>
        <reference source="CVE" ref_id="CVE-2014-4252" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4252.html"/>
        <reference source="CVE" ref_id="CVE-2014-4262" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4262.html"/>
        <reference source="CVE" ref_id="CVE-2014-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4263.html"/>
        <reference source="CVE" ref_id="CVE-2014-4266" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4266.html"/>
        <description>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

It was discovered that the Hotspot component in OpenJDK did not properly
verify bytecode from the class files. An untrusted Java application or
applet could possibly use these flaws to bypass Java sandbox restrictions.
(CVE-2014-4216, CVE-2014-4219)

A format string flaw was discovered in the Hotspot component event logger
in OpenJDK. An untrusted Java application or applet could use this flaw to
crash the Java Virtual Machine or, potentially, execute arbitrary code with
the privileges of the Java Virtual Machine. (CVE-2014-2490)

Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-4223,
CVE-2014-4262, CVE-2014-2483)

Multiple flaws were discovered in the JMX, Libraries, Security, and
Serviceability components in OpenJDK. An untrusted Java application or
applet could use these flaws to bypass certain Java sandbox restrictions.
(CVE-2014-4209, CVE-2014-4218, CVE-2014-4221, CVE-2014-4252, CVE-2014-4266)

It was discovered that the RSA algorithm in the Security component in
OpenJDK did not sufficiently perform blinding while performing operations
that were using private keys. An attacker able to measure timing
differences of those operations could possibly leak information about the
used keys. (CVE-2014-4244)

The Diffie-Hellman (DH) key exchange algorithm implementation in the
Security component in OpenJDK failed to validate public DH parameters
properly. This could cause OpenJDK to accept and use weak parameters,
allowing an attacker to recover the negotiated key. (CVE-2014-4263)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:01:08.742-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:02:58.703-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:00:38.505-04:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-11T18:28:40.534-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-11T18:28:40.534-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.65-2.5.1.2.el5_10" test_ref="oval:org.mitre.oval:tst:116108"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.65-2.5.1.2.el5_10" test_ref="oval:org.mitre.oval:tst:115860"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.65-2.5.1.2.el5_10" test_ref="oval:org.mitre.oval:tst:116014"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.65-2.5.1.2.el5_10" test_ref="oval:org.mitre.oval:tst:116065"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.65-2.5.1.2.el5_10" test_ref="oval:org.mitre.oval:tst:115774"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24845" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0448: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0448-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0448.html"/>
        <reference source="CESA" ref_id="CESA-2014:0448"/>
        <reference source="CVE" ref_id="CVE-2014-1518" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1518.html"/>
        <reference source="CVE" ref_id="CVE-2014-1523" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1523.html"/>
        <reference source="CVE" ref_id="CVE-2014-1524" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1524.html"/>
        <reference source="CVE" ref_id="CVE-2014-1529" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1529.html"/>
        <reference source="CVE" ref_id="CVE-2014-1530" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1530.html"/>
        <reference source="CVE" ref_id="CVE-2014-1531" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1531.html"/>
        <reference source="CVE" ref_id="CVE-2014-1532" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1532.html"/>
        <description>Mozilla Firefox is an open source web browser.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1518, CVE-2014-1524, CVE-2014-1529, CVE-2014-1531)

A use-after-free flaw was found in the way Firefox resolved hosts in
certain circumstances. An attacker could use this flaw to crash Firefox or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1532)

An out-of-bounds read flaw was found in the way Firefox decoded JPEG
images. Loading a web page containing a specially crafted JPEG image could
cause Firefox to crash. (CVE-2014-1523)

A flaw was found in the way Firefox handled browser navigations through
history. An attacker could possibly use this flaw to cause the address bar
of the browser to display a web page name while loading content from an
entirely different web page, which could allow for cross-site scripting
(XSS) attacks. (CVE-2014-1530)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bobby Holley, Carsten Book, Christoph Diehl, Gary
Kwong, Jan de Mooij, Jesse Ruderman, Nathan Froyd, Christian Holler,
Abhishek Arya, Mariusz Mlynski, moz_bug_r_a4, Nils, Tyson Smith, and Jesse
Schwartzentrube as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.5.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to this updated package, which contains
Firefox version 24.5.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-21T16:07:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-05-23T10:29:14.634-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:42.250-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:56.642-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:24.5.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:113595"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:24.5.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:113371"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="firefox is earlier than 0:24.5.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:114141"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="firefox is earlier than 0:24.5.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:114160"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24842" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0745: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0745-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0745.html"/>
        <reference source="CVE" ref_id="CVE-2014-0531" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0531.html"/>
        <reference source="CVE" ref_id="CVE-2014-0532" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0532.html"/>
        <reference source="CVE" ref_id="CVE-2014-0533" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0533.html"/>
        <reference source="CVE" ref_id="CVE-2014-0534" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0534.html"/>
        <reference source="CVE" ref_id="CVE-2014-0535" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0535.html"/>
        <reference source="CVE" ref_id="CVE-2014-0536" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0536.html"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed in the Adobe Security Bulletin APSB14-16,
listed in the References section.

Multiple flaws were found in the way flash-plugin displayed certain SWF
content. An attacker could use these flaws to create a specially crafted
SWF file that would cause flash-plugin to crash or, potentially, execute
arbitrary code when the victim loaded a page containing the malicious SWF
content. (CVE-2014-0534, CVE-2014-0535, CVE-2014-0536)

Multiple flaws in flash-plugin could allow an attacker to conduct
cross-site scripting (XSS) attacks if a victim were tricked into visiting a
specially crafted web page. (CVE-2014-0531, CVE-2014-0532, CVE-2014-0533)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.378.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:01:27.408-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:02:50.614-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:00:30.598-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.378-1.el5" test_ref="oval:org.mitre.oval:tst:115747"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.378-1.el6" test_ref="oval:org.mitre.oval:tst:115295"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24829" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0449: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0449-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0449.html"/>
        <reference source="CESA" ref_id="CESA-2014:0449"/>
        <reference source="CVE" ref_id="CVE-2014-1518" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1518.html"/>
        <reference source="CVE" ref_id="CVE-2014-1523" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1523.html"/>
        <reference source="CVE" ref_id="CVE-2014-1524" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1524.html"/>
        <reference source="CVE" ref_id="CVE-2014-1529" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1529.html"/>
        <reference source="CVE" ref_id="CVE-2014-1530" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1530.html"/>
        <reference source="CVE" ref_id="CVE-2014-1531" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1531.html"/>
        <reference source="CVE" ref_id="CVE-2014-1532" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1532.html"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1518, CVE-2014-1524, CVE-2014-1529, CVE-2014-1531)

A use-after-free flaw was found in the way Thunderbird resolved hosts in
certain circumstances. An attacker could use this flaw to crash Thunderbird
or, potentially, execute arbitrary code with the privileges of the user
running Thunderbird. (CVE-2014-1532)

An out-of-bounds read flaw was found in the way Thunderbird decoded JPEG
images. Loading an email or a web page containing a specially crafted JPEG
image could cause Thunderbird to crash. (CVE-2014-1523)

A flaw was found in the way Thunderbird handled browser navigations through
history. An attacker could possibly use this flaw to cause the address bar
of the browser to display a web page name while loading content from an
entirely different web page, which could allow for cross-site scripting
(XSS) attacks. (CVE-2014-1530)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bobby Holley, Carsten Book, Christoph Diehl, Gary
Kwong, Jan de Mooij, Jesse Ruderman, Nathan Froyd, Christian Holler,
Abhishek Arya, Mariusz Mlynski, moz_bug_r_a4, Nils, Tyson Smith and Jesse
Schwartzentrube as the original reporters of these issues.

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.5.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.5.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-21T16:07:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-05-23T10:29:07.788-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:40.996-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:55.081-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:114348"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:113987"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:114036"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:114360"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24812" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0918: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0918-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0918.html"/>
        <reference source="CESA" ref_id="CESA-2014:0918"/>
        <reference source="CVE" ref_id="CVE-2014-1547" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1547.html"/>
        <reference source="CVE" ref_id="CVE-2014-1555" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1555.html"/>
        <reference source="CVE" ref_id="CVE-2014-1556" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1556.html"/>
        <reference source="CVE" ref_id="CVE-2014-1557" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1557.html"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1547, CVE-2014-1555, CVE-2014-1556, CVE-2014-1557)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Christian Holler, David Keeler, Byron Campen, Jethro
Beekman, Patrick Cozzi, and Mozilla community member John as the original
reporters of these issues.

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.7.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.7.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:01:13.375-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:02:49.553-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:00:28.841-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:24.7.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:116050"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:24.7.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:116162"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:24.7.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:116061"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:24.7.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:116004"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24794" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0509: java-1.5.0-ibm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0509-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0509.html"/>
        <reference source="CVE" ref_id="CVE-2013-6629" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6629.html"/>
        <reference source="CVE" ref_id="CVE-2014-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0429.html"/>
        <reference source="CVE" ref_id="CVE-2014-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0446.html"/>
        <reference source="CVE" ref_id="CVE-2014-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0451.html"/>
        <reference source="CVE" ref_id="CVE-2014-0453" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0453.html"/>
        <reference source="CVE" ref_id="CVE-2014-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0457.html"/>
        <reference source="CVE" ref_id="CVE-2014-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0460.html"/>
        <reference source="CVE" ref_id="CVE-2014-1876" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1876.html"/>
        <reference source="CVE" ref_id="CVE-2014-2398" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2398.html"/>
        <reference source="CVE" ref_id="CVE-2014-2401" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2401.html"/>
        <reference source="CVE" ref_id="CVE-2014-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2412.html"/>
        <reference source="CVE" ref_id="CVE-2014-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2421.html"/>
        <reference source="CVE" ref_id="CVE-2014-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2427.html"/>
        <description>IBM J2SE version 5.0 includes the IBM Java Runtime Environment and the IBM
Java Software Development Kit.

This update fixes several vulnerabilities in the IBM Java Runtime
Environment and the IBM Java Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM Security alerts
page, listed in the References section. (CVE-2014-0457, CVE-2014-2421,
CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-2427, CVE-2014-2412,
CVE-2014-0460, CVE-2013-6629, CVE-2014-2401, CVE-2014-0453, CVE-2014-2398,
CVE-2014-1876)

All users of java-1.5.0-ibm are advised to upgrade to these updated
packages, containing the IBM J2SE 5.0 SR16-FP6 release. All running
instances of IBM Java must be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-21T16:07:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-05-23T10:29:13.676-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:39.106-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:53.094-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114294"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114004"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:113772"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114392"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114331"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114275"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:113837"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114370"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113443"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113811"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114061"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114358"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113923"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114373"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114414"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24789" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0496: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0496-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0496.html"/>
        <reference source="CVE" ref_id="CVE-2014-0510" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0510.html"/>
        <reference source="CVE" ref_id="CVE-2014-0516" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0516.html"/>
        <reference source="CVE" ref_id="CVE-2014-0517" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0517.html"/>
        <reference source="CVE" ref_id="CVE-2014-0518" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0518.html"/>
        <reference source="CVE" ref_id="CVE-2014-0519" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0519.html"/>
        <reference source="CVE" ref_id="CVE-2014-0520" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0520.html"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed in the Adobe Security Bulletin APSB14-14,
listed in the References section.

Multiple flaws were found in the way flash-plugin displayed certain SWF
content. An attacker could use these flaws to create a specially crafted
SWF file that would cause flash-plugin to crash or, potentially, execute
arbitrary code when the victim loaded a page containing the malicious SWF
content. (CVE-2014-0510, CVE-2014-0517, CVE-2014-0518, CVE-2014-0519,
CVE-2014-0520)

A flaw in flash-plugin could allow an attacker to bypass the same-origin
policy. (CVE-2014-0516)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.359.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-21T16:07:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-05-23T10:29:09.431-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:38.612-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:52.746-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.359-1.el5" test_ref="oval:org.mitre.oval:tst:114364"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.359-1.el6" test_ref="oval:org.mitre.oval:tst:113835"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24772" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0624: openssl security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0624-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0624.html"/>
        <reference source="CESA" ref_id="CESA-2014:0624"/>
        <reference source="CVE" ref_id="CVE-2014-0224" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0224.html"/>
        <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

It was found that OpenSSL clients and servers could be forced, via a
specially crafted handshake packet, to use weak keying material for
communication. A man-in-the-middle attacker could use this flaw to decrypt
and modify traffic between a client and a server. (CVE-2014-0224)

Note: In order to exploit this flaw, both the server and the client must be
using a vulnerable version of OpenSSL; the server must be using OpenSSL
version 1.0.1 and above, and the client must be using any version of
OpenSSL. For more information about this flaw, refer to:
https://access.redhat.com/site/articles/904433

Red Hat would like to thank the OpenSSL project for reporting this issue.
Upstream acknowledges KIKUCHI Masashi of Lepidum as the original reporter
of this issue.

All OpenSSL users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-09T15:16:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-06-10T14:50:22.356-04:00">DRAFT</status_change>
            <status_change date="2014-06-30T04:10:51.366-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:40.928-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-27.el5_10.3" test_ref="oval:org.mitre.oval:tst:114855"/>
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-27.el5_10.3" test_ref="oval:org.mitre.oval:tst:114504"/>
          <criterion comment="openssl is earlier than 0:0.9.8e-27.el5_10.3" test_ref="oval:org.mitre.oval:tst:114534"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24735" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0474: struts security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>struts</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0474-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0474.html"/>
        <reference source="CESA" ref_id="CESA-2014:0474"/>
        <reference source="CVE" ref_id="CVE-2014-0114" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0114.html"/>
        <description>Apache Struts is a framework for building web applications with Java.

It was found that the Struts 1 ActionForm object allowed access to the
'class' parameter, which is directly mapped to the getClass() method. A
remote attacker could use this flaw to manipulate the ClassLoader used by
an application server running Struts 1. This could lead to remote code
execution under certain conditions. (CVE-2014-0114)

All struts users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. All running applications
using struts must be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-21T16:07:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-05-23T10:29:09.985-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:28.703-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:41.754-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="struts-manual is earlier than 0:1.2.9-4jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:114303"/>
          <criterion comment="struts is earlier than 0:1.2.9-4jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:114297"/>
          <criterion comment="struts-javadoc is earlier than 0:1.2.9-4jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:113380"/>
          <criterion comment="struts-webapps-tomcat5 is earlier than 0:1.2.9-4jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:114193"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24734" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0594: gnutls security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0594-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0594.html"/>
        <reference source="CESA" ref_id="CESA-2014:0594"/>
        <reference source="CVE" ref_id="CVE-2014-3466" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3466.html"/>
        <reference source="CVE" ref_id="CVE-2014-3467" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3467.html"/>
        <reference source="CVE" ref_id="CVE-2014-3468" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3468.html"/>
        <reference source="CVE" ref_id="CVE-2014-3469" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3469.html"/>
        <description>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS). The gnutls packages also
include the libtasn1 library, which provides Abstract Syntax Notation One
(ASN.1) parsing and structures management, and Distinguished Encoding Rules
(DER) encoding and decoding functions.

A flaw was found in the way GnuTLS parsed session IDs from ServerHello
messages of the TLS/SSL handshake. A malicious server could use this flaw
to send an excessively long session ID value, which would trigger a buffer
overflow in a connecting TLS/SSL client application using GnuTLS, causing
the client application to crash or, possibly, execute arbitrary code.
(CVE-2014-3466)

It was discovered that the asn1_get_bit_der() function of the libtasn1
library incorrectly reported the length of ASN.1-encoded data. Specially
crafted ASN.1 input could cause an application using libtasn1 to perform
an out-of-bounds access operation, causing the application to crash or,
possibly, execute arbitrary code. (CVE-2014-3468)

Multiple incorrect buffer boundary check issues were discovered in
libtasn1. Specially crafted ASN.1 input could cause an application using
libtasn1 to crash. (CVE-2014-3467)

Multiple NULL pointer dereference flaws were found in libtasn1's
asn1_read_value() function. Specially crafted ASN.1 input could cause an
application using libtasn1 to crash, if the application used the
aforementioned function in a certain way. (CVE-2014-3469)

Red Hat would like to thank GnuTLS upstream for reporting these issues.
Upstream acknowledges Joonas Kuorilehto of Codenomicon as the original
reporter of CVE-2014-3466.

Users of GnuTLS are advised to upgrade to these updated packages, which
correct these issues. For the update to take effect, all applications
linked to the GnuTLS or libtasn1 library must be restarted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-09T15:16:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-06-10T14:50:19.971-04:00">DRAFT</status_change>
            <status_change date="2014-06-30T04:10:41.485-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:32.968-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="gnutls is earlier than 0:1.4.1-16.el5_10" test_ref="oval:org.mitre.oval:tst:114900"/>
          <criterion comment="gnutls-devel is earlier than 0:1.4.1-16.el5_10" test_ref="oval:org.mitre.oval:tst:114636"/>
          <criterion comment="gnutls-utils is earlier than 0:1.4.1-16.el5_10" test_ref="oval:org.mitre.oval:tst:114627"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24723" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0413: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0413-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0413.html"/>
        <reference source="CVE" ref_id="CVE-2013-6629" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6629.html"/>
        <reference source="CVE" ref_id="CVE-2013-6954" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6954.html"/>
        <reference source="CVE" ref_id="CVE-2014-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0429.html"/>
        <reference source="CVE" ref_id="CVE-2014-0432" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0432.html"/>
        <reference source="CVE" ref_id="CVE-2014-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0446.html"/>
        <reference source="CVE" ref_id="CVE-2014-0448" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0448.html"/>
        <reference source="CVE" ref_id="CVE-2014-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0449.html"/>
        <reference source="CVE" ref_id="CVE-2014-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0451.html"/>
        <reference source="CVE" ref_id="CVE-2014-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0452.html"/>
        <reference source="CVE" ref_id="CVE-2014-0453" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0453.html"/>
        <reference source="CVE" ref_id="CVE-2014-0454" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0454.html"/>
        <reference source="CVE" ref_id="CVE-2014-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0455.html"/>
        <reference source="CVE" ref_id="CVE-2014-0456" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0456.html"/>
        <reference source="CVE" ref_id="CVE-2014-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0457.html"/>
        <reference source="CVE" ref_id="CVE-2014-0458" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0458.html"/>
        <reference source="CVE" ref_id="CVE-2014-0459" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0459.html"/>
        <reference source="CVE" ref_id="CVE-2014-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0460.html"/>
        <reference source="CVE" ref_id="CVE-2014-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0461.html"/>
        <reference source="CVE" ref_id="CVE-2014-1876" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1876.html"/>
        <reference source="CVE" ref_id="CVE-2014-2397" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2397.html"/>
        <reference source="CVE" ref_id="CVE-2014-2398" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2398.html"/>
        <reference source="CVE" ref_id="CVE-2014-2401" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2401.html"/>
        <reference source="CVE" ref_id="CVE-2014-2402" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2402.html"/>
        <reference source="CVE" ref_id="CVE-2014-2403" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2403.html"/>
        <reference source="CVE" ref_id="CVE-2014-2409" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2409.html"/>
        <reference source="CVE" ref_id="CVE-2014-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2412.html"/>
        <reference source="CVE" ref_id="CVE-2014-2413" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2413.html"/>
        <reference source="CVE" ref_id="CVE-2014-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2414.html"/>
        <reference source="CVE" ref_id="CVE-2014-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2420.html"/>
        <reference source="CVE" ref_id="CVE-2014-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2421.html"/>
        <reference source="CVE" ref_id="CVE-2014-2422" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2422.html"/>
        <reference source="CVE" ref_id="CVE-2014-2423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2423.html"/>
        <reference source="CVE" ref_id="CVE-2014-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2427.html"/>
        <reference source="CVE" ref_id="CVE-2014-2428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2428.html"/>
        <description>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2013-6629, CVE-2013-6954, CVE-2014-0429, CVE-2014-0432, CVE-2014-0446,
CVE-2014-0448, CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453,
CVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,
CVE-2014-0459, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876, CVE-2014-2397,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2402, CVE-2014-2403, CVE-2014-2409,
CVE-2014-2412, CVE-2014-2413, CVE-2014-2414, CVE-2014-2420, CVE-2014-2421,
CVE-2014-2422, CVE-2014-2423, CVE-2014-2427, CVE-2014-2428)

All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 55 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-24T11:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-30T15:07:59.673-04:00">DRAFT</status_change>
            <status_change date="2014-05-19T04:00:28.442-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:01:26.686-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113900"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113949"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113941"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113976"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113955"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113612"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113277"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113802"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113525"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113785"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113074"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113657"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24670" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0742: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0742-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0742.html"/>
        <reference source="CESA" ref_id="CESA-2014:0742"/>
        <reference source="CVE" ref_id="CVE-2014-1533" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1533.html"/>
        <reference source="CVE" ref_id="CVE-2014-1538" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1538.html"/>
        <reference source="CVE" ref_id="CVE-2014-1541" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1541.html"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1533, CVE-2014-1538, CVE-2014-1541)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Christoph Diehl, Christian Holler, Hannes
Verschore, Jan de Mooij, Ryan VanderMeulen, Jeff Walden, Kyle Huey,
Abhishek Arya, and Nils as the original reporters of these issues.

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.6.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.6.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-02T17:22:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-07T16:13:34.219-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:25.793-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:42.146-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:24.6.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:115597"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:24.6.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:115066"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:24.6.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:115511"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:24.6.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:115386"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24650" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0447: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0447-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0447.html"/>
        <reference source="CVE" ref_id="CVE-2014-0515" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0515.html"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes one vulnerability in Adobe Flash Player. This
vulnerability is detailed in the Adobe Security Bulletin APSB14-13, listed
in the References section.

A flaw was found in the way flash-plugin displayed certain SWF content. An
attacker could use this flaw to create a specially crafted SWF file that
would cause flash-plugin to crash or, potentially, execute arbitrary code
when the victim loaded a page containing the malicious SWF content.
(CVE-2014-0515)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.356.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-21T16:07:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-05-23T10:29:12.471-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:20.303-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:36.113-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.356-1.el5" test_ref="oval:org.mitre.oval:tst:114008"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.356-1.el6" test_ref="oval:org.mitre.oval:tst:114013"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24641" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0407: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0407-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0407.html"/>
        <reference source="CESA" ref_id="CESA-2014:0407"/>
        <reference source="CVE" ref_id="CVE-2014-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0429.html"/>
        <reference source="CVE" ref_id="CVE-2014-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0446.html"/>
        <reference source="CVE" ref_id="CVE-2014-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0451.html"/>
        <reference source="CVE" ref_id="CVE-2014-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0452.html"/>
        <reference source="CVE" ref_id="CVE-2014-0453" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0453.html"/>
        <reference source="CVE" ref_id="CVE-2014-0454" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0454.html"/>
        <reference source="CVE" ref_id="CVE-2014-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0455.html"/>
        <reference source="CVE" ref_id="CVE-2014-0456" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0456.html"/>
        <reference source="CVE" ref_id="CVE-2014-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0457.html"/>
        <reference source="CVE" ref_id="CVE-2014-0458" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0458.html"/>
        <reference source="CVE" ref_id="CVE-2014-0459" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0459.html"/>
        <reference source="CVE" ref_id="CVE-2014-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0460.html"/>
        <reference source="CVE" ref_id="CVE-2014-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0461.html"/>
        <reference source="CVE" ref_id="CVE-2014-1876" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1876.html"/>
        <reference source="CVE" ref_id="CVE-2014-2397" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2397.html"/>
        <reference source="CVE" ref_id="CVE-2014-2398" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2398.html"/>
        <reference source="CVE" ref_id="CVE-2014-2402" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2402.html"/>
        <reference source="CVE" ref_id="CVE-2014-2403" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2403.html"/>
        <reference source="CVE" ref_id="CVE-2014-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2412.html"/>
        <reference source="CVE" ref_id="CVE-2014-2413" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2413.html"/>
        <reference source="CVE" ref_id="CVE-2014-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2414.html"/>
        <reference source="CVE" ref_id="CVE-2014-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2421.html"/>
        <reference source="CVE" ref_id="CVE-2014-2423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2423.html"/>
        <reference source="CVE" ref_id="CVE-2014-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2427.html"/>
        <description>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

An input validation flaw was discovered in the medialib library in the 2D
component. A specially crafted image could trigger Java Virtual Machine
memory corruption when processed. A remote attacker, or an untrusted Java
application or applet, could possibly use this flaw to execute arbitrary
code with the privileges of the user running the Java Virtual Machine.
(CVE-2014-0429)

Multiple flaws were discovered in the Hotspot and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to trigger
Java Virtual Machine memory corruption and possibly bypass Java sandbox
restrictions. (CVE-2014-0456, CVE-2014-2397, CVE-2014-2421)

Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-0457,
CVE-2014-0455, CVE-2014-0461)

Multiple improper permission check issues were discovered in the AWT,
JAX-WS, JAXB, Libraries, Security, Sound, and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to bypass
certain Java sandbox restrictions. (CVE-2014-2412, CVE-2014-0451,
CVE-2014-0458, CVE-2014-2423, CVE-2014-0452, CVE-2014-2414, CVE-2014-2402,
CVE-2014-0446, CVE-2014-2413, CVE-2014-0454, CVE-2014-2427, CVE-2014-0459)

Multiple flaws were identified in the Java Naming and Directory Interface
(JNDI) DNS client. These flaws could make it easier for a remote attacker
to perform DNS spoofing attacks. (CVE-2014-0460)

It was discovered that the JAXP component did not properly prevent access
to arbitrary files when a SecurityManager was present. This flaw could
cause a Java application using JAXP to leak sensitive information, or
affect application availability. (CVE-2014-2403)

It was discovered that the Security component in OpenJDK could leak some
timing information when performing PKCS#1 unpadding. This could possibly
lead to the disclosure of some information that was meant to be protected
by encryption. (CVE-2014-0453)

It was discovered that the fix for CVE-2013-5797 did not properly resolve
input sanitization flaws in javadoc. When javadoc documentation was
generated from an untrusted Java source code and hosted on a domain not
controlled by the code author, these issues could make it easier to perform
cross-site scripting (XSS) attacks. (CVE-2014-2398)

An insecure temporary file use flaw was found in the way the unpack200
utility created log files. A local attacker could possibly use this flaw to
perform a symbolic link attack and overwrite arbitrary files with the
privileges of the user running unpack200. (CVE-2014-1876)

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-24T11:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-30T15:07:58.764-04:00">DRAFT</status_change>
            <status_change date="2014-05-19T04:00:26.821-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:01:17.642-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.55-2.4.7.1.el5_10" test_ref="oval:org.mitre.oval:tst:114006"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.55-2.4.7.1.el5_10" test_ref="oval:org.mitre.oval:tst:113915"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.55-2.4.7.1.el5_10" test_ref="oval:org.mitre.oval:tst:113255"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.55-2.4.7.1.el5_10" test_ref="oval:org.mitre.oval:tst:113375"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.55-2.4.7.1.el5_10" test_ref="oval:org.mitre.oval:tst:113927"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24575" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0433: kernel security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0433-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0433.html"/>
        <reference source="CESA" ref_id="CESA-2014:0433"/>
        <reference source="CVE" ref_id="CVE-2012-6638" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6638.html"/>
        <reference source="CVE" ref_id="CVE-2013-2888" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2888.html"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's TCP/IP protocol suite
implementation handled TCP packets with both the SYN and FIN flags set.
A remote attacker could use this flaw to consume an excessive amount of
resources on the target system, potentially resulting in a denial of
service. (CVE-2012-6638, Moderate)

* A flaw was found in the way the Linux kernel handled HID (Human Interface
Device) reports with an out-of-bounds Report ID. An attacker with physical
access to the system could use this flaw to crash the system or,
potentially, escalate their privileges on the system. (CVE-2013-2888,
Moderate)

This update also fixes the following bugs:

* A previous change to the sunrpc code introduced a race condition between
the rpc_wake_up_task() and rpc_wake_up_status() functions. A race between
threads operating on these functions could result in a deadlock situation,
subsequently triggering a "soft lockup" event and rendering the system
unresponsive. This problem has been fixed by re-ordering tasks in the RPC
wait queue. (BZ#1073731)

* Running a process in the background on a GFS2 file system could
sometimes trigger a glock recursion error that resulted in a kernel panic.
This happened when a readpage operation attempted to take a glock that had
already been held by another function. To prevent this error, GFS2 now
verifies whether the glock is already held when performing the readpage
operation. (BZ#1073953)

* A previous patch backport to the IUCV (Inter User Communication Vehicle)
code was incomplete. Consequently, when establishing an IUCV connection,
the kernel could, under certain circumstances, dereference a NULL pointer,
resulting in a kernel panic. A patch has been applied to correct this
problem by calling the proper function when removing IUCV paths.
(BZ#1077045)

In addition, this update adds the following enhancement:

* The lpfc driver had a fixed timeout of 60 seconds for SCSI task
management commands. With this update, the lpfc driver enables the user to
set this timeout within the range from 5 to 180 seconds. The timeout can
be changed by modifying the "lpfc_task_mgmt_tmo" parameter for the lpfc
driver. (BZ#1073123)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add this
enhancement. The system must be rebooted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-21T16:07:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-05-23T10:29:08.547-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:01.249-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:24.381-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:114292"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:114204"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:113995"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:113719"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:114139"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:114176"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:114045"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:114302"/>
          <criterion comment="kernel is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:113814"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:113886"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:114286"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:114117"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24557" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0414: java-1.6.0-sun security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0414-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0414.html"/>
        <reference source="CVE" ref_id="CVE-2013-1500" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1500.html"/>
        <reference source="CVE" ref_id="CVE-2013-1571" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1571.html"/>
        <reference source="CVE" ref_id="CVE-2013-2407" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2407.html"/>
        <reference source="CVE" ref_id="CVE-2013-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2412.html"/>
        <reference source="CVE" ref_id="CVE-2013-2437" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2437.html"/>
        <reference source="CVE" ref_id="CVE-2013-2442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2442.html"/>
        <reference source="CVE" ref_id="CVE-2013-2443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2443.html"/>
        <reference source="CVE" ref_id="CVE-2013-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2444.html"/>
        <reference source="CVE" ref_id="CVE-2013-2445" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2445.html"/>
        <reference source="CVE" ref_id="CVE-2013-2446" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2446.html"/>
        <reference source="CVE" ref_id="CVE-2013-2447" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2447.html"/>
        <reference source="CVE" ref_id="CVE-2013-2448" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2448.html"/>
        <reference source="CVE" ref_id="CVE-2013-2450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2450.html"/>
        <reference source="CVE" ref_id="CVE-2013-2451" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2451.html"/>
        <reference source="CVE" ref_id="CVE-2013-2452" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2452.html"/>
        <reference source="CVE" ref_id="CVE-2013-2453" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2453.html"/>
        <reference source="CVE" ref_id="CVE-2013-2454" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2454.html"/>
        <reference source="CVE" ref_id="CVE-2013-2455" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2455.html"/>
        <reference source="CVE" ref_id="CVE-2013-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2456.html"/>
        <reference source="CVE" ref_id="CVE-2013-2457" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2457.html"/>
        <reference source="CVE" ref_id="CVE-2013-2459" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2459.html"/>
        <reference source="CVE" ref_id="CVE-2013-2461" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2461.html"/>
        <reference source="CVE" ref_id="CVE-2013-2463" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2463.html"/>
        <reference source="CVE" ref_id="CVE-2013-2464" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2464.html"/>
        <reference source="CVE" ref_id="CVE-2013-2465" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2465.html"/>
        <reference source="CVE" ref_id="CVE-2013-2466" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2466.html"/>
        <reference source="CVE" ref_id="CVE-2013-2468" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2468.html"/>
        <reference source="CVE" ref_id="CVE-2013-2469" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2469.html"/>
        <reference source="CVE" ref_id="CVE-2013-2470" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2470.html"/>
        <reference source="CVE" ref_id="CVE-2013-2471" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2471.html"/>
        <reference source="CVE" ref_id="CVE-2013-2472" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2472.html"/>
        <reference source="CVE" ref_id="CVE-2013-2473" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2473.html"/>
        <reference source="CVE" ref_id="CVE-2013-3743" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3743.html"/>
        <reference source="CVE" ref_id="CVE-2013-3829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3829.html"/>
        <reference source="CVE" ref_id="CVE-2013-4002" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4002.html"/>
        <reference source="CVE" ref_id="CVE-2013-5772" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5772.html"/>
        <reference source="CVE" ref_id="CVE-2013-5774" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5774.html"/>
        <reference source="CVE" ref_id="CVE-2013-5776" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5776.html"/>
        <reference source="CVE" ref_id="CVE-2013-5778" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5778.html"/>
        <reference source="CVE" ref_id="CVE-2013-5780" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5780.html"/>
        <reference source="CVE" ref_id="CVE-2013-5782" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5782.html"/>
        <reference source="CVE" ref_id="CVE-2013-5783" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5783.html"/>
        <reference source="CVE" ref_id="CVE-2013-5784" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5784.html"/>
        <reference source="CVE" ref_id="CVE-2013-5787" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5787.html"/>
        <reference source="CVE" ref_id="CVE-2013-5789" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5789.html"/>
        <reference source="CVE" ref_id="CVE-2013-5790" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5790.html"/>
        <reference source="CVE" ref_id="CVE-2013-5797" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5797.html"/>
        <reference source="CVE" ref_id="CVE-2013-5801" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5801.html"/>
        <reference source="CVE" ref_id="CVE-2013-5802" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5802.html"/>
        <reference source="CVE" ref_id="CVE-2013-5803" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5803.html"/>
        <reference source="CVE" ref_id="CVE-2013-5804" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5804.html"/>
        <reference source="CVE" ref_id="CVE-2013-5809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5809.html"/>
        <reference source="CVE" ref_id="CVE-2013-5812" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5812.html"/>
        <reference source="CVE" ref_id="CVE-2013-5814" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5814.html"/>
        <reference source="CVE" ref_id="CVE-2013-5817" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5817.html"/>
        <reference source="CVE" ref_id="CVE-2013-5818" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5818.html"/>
        <reference source="CVE" ref_id="CVE-2013-5819" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5819.html"/>
        <reference source="CVE" ref_id="CVE-2013-5820" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5820.html"/>
        <reference source="CVE" ref_id="CVE-2013-5823" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5823.html"/>
        <reference source="CVE" ref_id="CVE-2013-5824" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5824.html"/>
        <reference source="CVE" ref_id="CVE-2013-5825" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5825.html"/>
        <reference source="CVE" ref_id="CVE-2013-5829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5829.html"/>
        <reference source="CVE" ref_id="CVE-2013-5830" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5830.html"/>
        <reference source="CVE" ref_id="CVE-2013-5831" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5831.html"/>
        <reference source="CVE" ref_id="CVE-2013-5832" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5832.html"/>
        <reference source="CVE" ref_id="CVE-2013-5840" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5840.html"/>
        <reference source="CVE" ref_id="CVE-2013-5842" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5842.html"/>
        <reference source="CVE" ref_id="CVE-2013-5843" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5843.html"/>
        <reference source="CVE" ref_id="CVE-2013-5848" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5848.html"/>
        <reference source="CVE" ref_id="CVE-2013-5849" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5849.html"/>
        <reference source="CVE" ref_id="CVE-2013-5850" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5850.html"/>
        <reference source="CVE" ref_id="CVE-2013-5852" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5852.html"/>
        <reference source="CVE" ref_id="CVE-2013-5878" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5878.html"/>
        <reference source="CVE" ref_id="CVE-2013-5884" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5884.html"/>
        <reference source="CVE" ref_id="CVE-2013-5887" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5887.html"/>
        <reference source="CVE" ref_id="CVE-2013-5888" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5888.html"/>
        <reference source="CVE" ref_id="CVE-2013-5889" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5889.html"/>
        <reference source="CVE" ref_id="CVE-2013-5896" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5896.html"/>
        <reference source="CVE" ref_id="CVE-2013-5898" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5898.html"/>
        <reference source="CVE" ref_id="CVE-2013-5899" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5899.html"/>
        <reference source="CVE" ref_id="CVE-2013-5902" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5902.html"/>
        <reference source="CVE" ref_id="CVE-2013-5905" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5905.html"/>
        <reference source="CVE" ref_id="CVE-2013-5906" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5906.html"/>
        <reference source="CVE" ref_id="CVE-2013-5907" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5907.html"/>
        <reference source="CVE" ref_id="CVE-2013-5910" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5910.html"/>
        <reference source="CVE" ref_id="CVE-2013-6629" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6629.html"/>
        <reference source="CVE" ref_id="CVE-2013-6954" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6954.html"/>
        <reference source="CVE" ref_id="CVE-2014-0368" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0368.html"/>
        <reference source="CVE" ref_id="CVE-2014-0373" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0373.html"/>
        <reference source="CVE" ref_id="CVE-2014-0375" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0375.html"/>
        <reference source="CVE" ref_id="CVE-2014-0376" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0376.html"/>
        <reference source="CVE" ref_id="CVE-2014-0387" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0387.html"/>
        <reference source="CVE" ref_id="CVE-2014-0403" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0403.html"/>
        <reference source="CVE" ref_id="CVE-2014-0410" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0410.html"/>
        <reference source="CVE" ref_id="CVE-2014-0411" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0411.html"/>
        <reference source="CVE" ref_id="CVE-2014-0415" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0415.html"/>
        <reference source="CVE" ref_id="CVE-2014-0416" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0416.html"/>
        <reference source="CVE" ref_id="CVE-2014-0417" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0417.html"/>
        <reference source="CVE" ref_id="CVE-2014-0418" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0418.html"/>
        <reference source="CVE" ref_id="CVE-2014-0422" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0422.html"/>
        <reference source="CVE" ref_id="CVE-2014-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0423.html"/>
        <reference source="CVE" ref_id="CVE-2014-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0424.html"/>
        <reference source="CVE" ref_id="CVE-2014-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0428.html"/>
        <reference source="CVE" ref_id="CVE-2014-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0429.html"/>
        <reference source="CVE" ref_id="CVE-2014-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0446.html"/>
        <reference source="CVE" ref_id="CVE-2014-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0449.html"/>
        <reference source="CVE" ref_id="CVE-2014-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0451.html"/>
        <reference source="CVE" ref_id="CVE-2014-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0452.html"/>
        <reference source="CVE" ref_id="CVE-2014-0453" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0453.html"/>
        <reference source="CVE" ref_id="CVE-2014-0456" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0456.html"/>
        <reference source="CVE" ref_id="CVE-2014-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0457.html"/>
        <reference source="CVE" ref_id="CVE-2014-0458" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0458.html"/>
        <reference source="CVE" ref_id="CVE-2014-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0460.html"/>
        <reference source="CVE" ref_id="CVE-2014-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0461.html"/>
        <reference source="CVE" ref_id="CVE-2014-1876" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1876.html"/>
        <reference source="CVE" ref_id="CVE-2014-2398" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2398.html"/>
        <reference source="CVE" ref_id="CVE-2014-2401" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2401.html"/>
        <reference source="CVE" ref_id="CVE-2014-2403" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2403.html"/>
        <reference source="CVE" ref_id="CVE-2014-2409" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2409.html"/>
        <reference source="CVE" ref_id="CVE-2014-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2412.html"/>
        <reference source="CVE" ref_id="CVE-2014-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2414.html"/>
        <reference source="CVE" ref_id="CVE-2014-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2420.html"/>
        <reference source="CVE" ref_id="CVE-2014-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2421.html"/>
        <reference source="CVE" ref_id="CVE-2014-2423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2423.html"/>
        <reference source="CVE" ref_id="CVE-2014-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2427.html"/>
        <reference source="CVE" ref_id="CVE-2014-2428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2428.html"/>
        <description>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory pages, listed in the References section.
(CVE-2013-1500, CVE-2013-1571, CVE-2013-2407, CVE-2013-2412, CVE-2013-2437,
CVE-2013-2442, CVE-2013-2443, CVE-2013-2444, CVE-2013-2445, CVE-2013-2446,
CVE-2013-2447, CVE-2013-2448, CVE-2013-2450, CVE-2013-2451, CVE-2013-2452,
CVE-2013-2453, CVE-2013-2454, CVE-2013-2455, CVE-2013-2456, CVE-2013-2457,
CVE-2013-2459, CVE-2013-2461, CVE-2013-2463, CVE-2013-2464, CVE-2013-2465,
CVE-2013-2466, CVE-2013-2468, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471,
CVE-2013-2472, CVE-2013-2473, CVE-2013-3743, CVE-2013-3829, CVE-2013-4002,
CVE-2013-5772, CVE-2013-5774, CVE-2013-5776, CVE-2013-5778, CVE-2013-5780,
CVE-2013-5782, CVE-2013-5783, CVE-2013-5784, CVE-2013-5787, CVE-2013-5789,
CVE-2013-5790, CVE-2013-5797, CVE-2013-5801, CVE-2013-5802, CVE-2013-5803,
CVE-2013-5804, CVE-2013-5809, CVE-2013-5812, CVE-2013-5814, CVE-2013-5817,
CVE-2013-5818, CVE-2013-5819, CVE-2013-5820, CVE-2013-5823, CVE-2013-5824,
CVE-2013-5825, CVE-2013-5829, CVE-2013-5830, CVE-2013-5831, CVE-2013-5832,
CVE-2013-5840, CVE-2013-5842, CVE-2013-5843, CVE-2013-5848, CVE-2013-5849,
CVE-2013-5850, CVE-2013-5852, CVE-2013-5878, CVE-2013-5884, CVE-2013-5887,
CVE-2013-5888, CVE-2013-5889, CVE-2013-5896, CVE-2013-5898, CVE-2013-5899,
CVE-2013-5902, CVE-2013-5905, CVE-2013-5906, CVE-2013-5907, CVE-2013-5910,
CVE-2013-6629, CVE-2013-6954, CVE-2014-0368, CVE-2014-0373, CVE-2014-0375,
CVE-2014-0376, CVE-2014-0387, CVE-2014-0403, CVE-2014-0410, CVE-2014-0411,
CVE-2014-0415, CVE-2014-0416, CVE-2014-0417, CVE-2014-0418, CVE-2014-0422,
CVE-2014-0423, CVE-2014-0424, CVE-2014-0428, CVE-2014-0429, CVE-2014-0446,
CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453, CVE-2014-0456,
CVE-2014-0457, CVE-2014-0458, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2403, CVE-2014-2409, CVE-2014-2412,
CVE-2014-2414, CVE-2014-2420, CVE-2014-2421, CVE-2014-2423, CVE-2014-2427,
CVE-2014-2428)

All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide Oracle Java 6 Update 75 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-24T11:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-30T15:07:54.944-04:00">DRAFT</status_change>
            <status_change date="2014-05-19T04:00:20.321-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:00:50.336-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114016"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113867"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113988"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113879"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114000"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113666"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:114032"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:113842"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:113239"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:113722"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:113781"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:114062"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24499" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:0369: httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0369-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0369.html"/>
        <reference source="CESA" ref_id="CESA-2014:0369"/>
        <reference source="CVE" ref_id="CVE-2013-6438" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6438.html"/>
        <reference source="CVE" ref_id="CVE-2014-0098" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0098.html"/>
        <description>The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-07T11:36:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-10T08:40:41.380-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:37.814-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:19.205-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="mod_ssl is earlier than 1:2.2.3-85.el5_10" test_ref="oval:org.mitre.oval:tst:113431"/>
            <criterion comment="httpd is earlier than 0:2.2.3-85.el5_10" test_ref="oval:org.mitre.oval:tst:113206"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-85.el5_10" test_ref="oval:org.mitre.oval:tst:113476"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-85.el5_10" test_ref="oval:org.mitre.oval:tst:113061"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="mod_ssl is earlier than 1:2.2.3-85.el5.centos" test_ref="oval:org.mitre.oval:tst:113417"/>
            <criterion comment="httpd is earlier than 0:2.2.3-85.el5.centos" test_ref="oval:org.mitre.oval:tst:113369"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-85.el5.centos" test_ref="oval:org.mitre.oval:tst:113392"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-85.el5.centos" test_ref="oval:org.mitre.oval:tst:113200"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24489" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0412: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0412-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0412.html"/>
        <reference source="CVE" ref_id="CVE-2013-6629" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6629.html"/>
        <reference source="CVE" ref_id="CVE-2013-6954" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6954.html"/>
        <reference source="CVE" ref_id="CVE-2014-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0429.html"/>
        <reference source="CVE" ref_id="CVE-2014-0432" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0432.html"/>
        <reference source="CVE" ref_id="CVE-2014-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0446.html"/>
        <reference source="CVE" ref_id="CVE-2014-0448" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0448.html"/>
        <reference source="CVE" ref_id="CVE-2014-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0449.html"/>
        <reference source="CVE" ref_id="CVE-2014-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0451.html"/>
        <reference source="CVE" ref_id="CVE-2014-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0452.html"/>
        <reference source="CVE" ref_id="CVE-2014-0453" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0453.html"/>
        <reference source="CVE" ref_id="CVE-2014-0454" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0454.html"/>
        <reference source="CVE" ref_id="CVE-2014-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0455.html"/>
        <reference source="CVE" ref_id="CVE-2014-0456" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0456.html"/>
        <reference source="CVE" ref_id="CVE-2014-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0457.html"/>
        <reference source="CVE" ref_id="CVE-2014-0458" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0458.html"/>
        <reference source="CVE" ref_id="CVE-2014-0459" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0459.html"/>
        <reference source="CVE" ref_id="CVE-2014-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0460.html"/>
        <reference source="CVE" ref_id="CVE-2014-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0461.html"/>
        <reference source="CVE" ref_id="CVE-2014-1876" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1876.html"/>
        <reference source="CVE" ref_id="CVE-2014-2397" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2397.html"/>
        <reference source="CVE" ref_id="CVE-2014-2398" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2398.html"/>
        <reference source="CVE" ref_id="CVE-2014-2401" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2401.html"/>
        <reference source="CVE" ref_id="CVE-2014-2402" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2402.html"/>
        <reference source="CVE" ref_id="CVE-2014-2403" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2403.html"/>
        <reference source="CVE" ref_id="CVE-2014-2409" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2409.html"/>
        <reference source="CVE" ref_id="CVE-2014-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2412.html"/>
        <reference source="CVE" ref_id="CVE-2014-2413" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2413.html"/>
        <reference source="CVE" ref_id="CVE-2014-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2414.html"/>
        <reference source="CVE" ref_id="CVE-2014-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2420.html"/>
        <reference source="CVE" ref_id="CVE-2014-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2421.html"/>
        <reference source="CVE" ref_id="CVE-2014-2422" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2422.html"/>
        <reference source="CVE" ref_id="CVE-2014-2423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2423.html"/>
        <reference source="CVE" ref_id="CVE-2014-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2427.html"/>
        <reference source="CVE" ref_id="CVE-2014-2428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2428.html"/>
        <description>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2013-6629, CVE-2013-6954, CVE-2014-0429, CVE-2014-0432, CVE-2014-0446,
CVE-2014-0448, CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453,
CVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,
CVE-2014-0459, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876, CVE-2014-2397,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2402, CVE-2014-2403, CVE-2014-2409,
CVE-2014-2412, CVE-2014-2413, CVE-2014-2414, CVE-2014-2420, CVE-2014-2421,
CVE-2014-2422, CVE-2014-2423, CVE-2014-2427, CVE-2014-2428)

All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 55 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-24T11:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-30T15:07:57.793-04:00">DRAFT</status_change>
            <status_change date="2014-05-19T04:00:17.577-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:00:45.270-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113277"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113802"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113525"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113785"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113074"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113657"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113900"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113949"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113941"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113976"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113955"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113612"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24446" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0508: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0508-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0508.html"/>
        <reference source="CVE" ref_id="CVE-2013-6629" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6629.html"/>
        <reference source="CVE" ref_id="CVE-2013-6954" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6954.html"/>
        <reference source="CVE" ref_id="CVE-2014-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0429.html"/>
        <reference source="CVE" ref_id="CVE-2014-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0446.html"/>
        <reference source="CVE" ref_id="CVE-2014-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0449.html"/>
        <reference source="CVE" ref_id="CVE-2014-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0451.html"/>
        <reference source="CVE" ref_id="CVE-2014-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0452.html"/>
        <reference source="CVE" ref_id="CVE-2014-0453" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0453.html"/>
        <reference source="CVE" ref_id="CVE-2014-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0457.html"/>
        <reference source="CVE" ref_id="CVE-2014-0458" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0458.html"/>
        <reference source="CVE" ref_id="CVE-2014-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0460.html"/>
        <reference source="CVE" ref_id="CVE-2014-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0461.html"/>
        <reference source="CVE" ref_id="CVE-2014-1876" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1876.html"/>
        <reference source="CVE" ref_id="CVE-2014-2398" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2398.html"/>
        <reference source="CVE" ref_id="CVE-2014-2401" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2401.html"/>
        <reference source="CVE" ref_id="CVE-2014-2409" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2409.html"/>
        <reference source="CVE" ref_id="CVE-2014-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2412.html"/>
        <reference source="CVE" ref_id="CVE-2014-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2414.html"/>
        <reference source="CVE" ref_id="CVE-2014-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2420.html"/>
        <reference source="CVE" ref_id="CVE-2014-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2421.html"/>
        <reference source="CVE" ref_id="CVE-2014-2423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2423.html"/>
        <reference source="CVE" ref_id="CVE-2014-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2427.html"/>
        <reference source="CVE" ref_id="CVE-2014-2428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2428.html"/>
        <description>IBM Java SE version 6 includes the IBM Java Runtime Environment and the IBM
Java Software Development Kit.

This update fixes several vulnerabilities in the IBM Java Runtime
Environment and the IBM Java Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM Security alerts
page, listed in the References section. (CVE-2014-0457, CVE-2014-2421,
CVE-2014-0429, CVE-2014-0461, CVE-2014-2428, CVE-2014-0446, CVE-2014-0452,
CVE-2014-0451, CVE-2014-2423, CVE-2014-2427, CVE-2014-0458, CVE-2014-2414,
CVE-2014-2412, CVE-2014-2409, CVE-2014-0460, CVE-2013-6954, CVE-2013-6629,
CVE-2014-2401, CVE-2014-0449, CVE-2014-0453, CVE-2014-2398, CVE-2014-1876,
CVE-2014-2420)

All users of java-1.6.0-ibm are advised to upgrade to these updated
packages, containing the IBM Java SE 6 SR16 release. All running instances
of IBM Java must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-21T16:07:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-05-23T10:29:15.401-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:41.478-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:17.898-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114248"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114111"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114189"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:113406"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:113822"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:113950"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:113426"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114381"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114372"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114304"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114046"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114256"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114217"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114359"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114333"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24444" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0408: java-1.6.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0408-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0408.html"/>
        <reference source="CESA" ref_id="CESA-2014:0408"/>
        <reference source="CVE" ref_id="CVE-2014-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0429.html"/>
        <reference source="CVE" ref_id="CVE-2014-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0446.html"/>
        <reference source="CVE" ref_id="CVE-2014-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0451.html"/>
        <reference source="CVE" ref_id="CVE-2014-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0452.html"/>
        <reference source="CVE" ref_id="CVE-2014-0453" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0453.html"/>
        <reference source="CVE" ref_id="CVE-2014-0456" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0456.html"/>
        <reference source="CVE" ref_id="CVE-2014-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0457.html"/>
        <reference source="CVE" ref_id="CVE-2014-0458" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0458.html"/>
        <reference source="CVE" ref_id="CVE-2014-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0460.html"/>
        <reference source="CVE" ref_id="CVE-2014-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0461.html"/>
        <reference source="CVE" ref_id="CVE-2014-1876" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1876.html"/>
        <reference source="CVE" ref_id="CVE-2014-2397" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2397.html"/>
        <reference source="CVE" ref_id="CVE-2014-2398" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2398.html"/>
        <reference source="CVE" ref_id="CVE-2014-2403" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2403.html"/>
        <reference source="CVE" ref_id="CVE-2014-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2412.html"/>
        <reference source="CVE" ref_id="CVE-2014-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2414.html"/>
        <reference source="CVE" ref_id="CVE-2014-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2421.html"/>
        <reference source="CVE" ref_id="CVE-2014-2423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2423.html"/>
        <reference source="CVE" ref_id="CVE-2014-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2427.html"/>
        <description>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.

An input validation flaw was discovered in the medialib library in the 2D
component. A specially crafted image could trigger Java Virtual Machine
memory corruption when processed. A remote attacker, or an untrusted Java
application or applet, could possibly use this flaw to execute arbitrary
code with the privileges of the user running the Java Virtual Machine.
(CVE-2014-0429)

Multiple flaws were discovered in the Hotspot and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to trigger
Java Virtual Machine memory corruption and possibly bypass Java sandbox
restrictions. (CVE-2014-0456, CVE-2014-2397, CVE-2014-2421)

Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-0457,
CVE-2014-0461)

Multiple improper permission check issues were discovered in the AWT,
JAX-WS, JAXB, Libraries, and Sound components in OpenJDK. An untrusted Java
application or applet could use these flaws to bypass certain Java sandbox
restrictions. (CVE-2014-2412, CVE-2014-0451, CVE-2014-0458, CVE-2014-2423,
CVE-2014-0452, CVE-2014-2414, CVE-2014-0446, CVE-2014-2427)

Multiple flaws were identified in the Java Naming and Directory Interface
(JNDI) DNS client. These flaws could make it easier for a remote attacker
to perform DNS spoofing attacks. (CVE-2014-0460)

It was discovered that the JAXP component did not properly prevent access
to arbitrary files when a SecurityManager was present. This flaw could
cause a Java application using JAXP to leak sensitive information, or
affect application availability. (CVE-2014-2403)

It was discovered that the Security component in OpenJDK could leak some
timing information when performing PKCS#1 unpadding. This could possibly
lead to the disclosure of some information that was meant to be protected
by encryption. (CVE-2014-0453)

It was discovered that the fix for CVE-2013-5797 did not properly resolve
input sanitization flaws in javadoc. When javadoc documentation was
generated from an untrusted Java source code and hosted on a domain not
controlled by the code author, these issues could make it easier to perform
cross-site scripting (XSS) attacks. (CVE-2014-2398)

An insecure temporary file use flaw was found in the way the unpack200
utility created log files. A local attacker could possibly use this flaw to
perform a symbolic link attack and overwrite arbitrary files with the
privileges of the user running unpack200. (CVE-2014-1876)

This update also fixes the following bug:

* The OpenJDK update to IcedTea version 1.13 introduced a regression
related to the handling of the jdk_version_info variable. This variable was
not properly zeroed out before being passed to the Java Virtual Machine,
resulting in a memory leak in the java.lang.ref.Finalizer class.
This update fixes this issue, and memory leaks no longer occur.
(BZ#1085373)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-24T11:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-30T15:07:53.004-04:00">DRAFT</status_change>
            <status_change date="2014-05-19T04:00:15.993-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:00:39.626-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:113830"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:113896"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:114024"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:113056"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:114041"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:113683"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:113861"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:113650"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:114057"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:113912"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24439" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:0380: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0380-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0380.html"/>
        <reference source="CVE" ref_id="CVE-2014-0506" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0506.html"/>
        <reference source="CVE" ref_id="CVE-2014-0507" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0507.html"/>
        <reference source="CVE" ref_id="CVE-2014-0508" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0508.html"/>
        <reference source="CVE" ref_id="CVE-2014-0509" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0509.html"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed in the Adobe Security Bulletin APSB14-09,
listed in the References section.

Two flaws were found in the way flash-plugin displayed certain SWF content.
An attacker could use these flaws to create a specially crafted SWF file
that would cause flash-plugin to crash or, potentially, execute arbitrary
code when the victim loaded a page containing the malicious SWF content.
(CVE-2014-0506, CVE-2014-0507)

A flaw in flash-plugin could allow an attacker to obtain sensitive
information if a victim were tricked into visiting a specially crafted web
page. (CVE-2014-0508)

A flaw in flash-plugin could allow an attacker to conduct cross-site
scripting (XSS) attacks if a victim were tricked into visiting a specially
crafted web page. (CVE-2014-0509)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.350.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-11T11:46:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-23T10:26:45.530-04:00">DRAFT</status_change>
            <status_change date="2014-05-12T04:00:54.348-04:00">INTERIM</status_change>
            <status_change date="2014-06-02T04:00:13.168-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24439 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:41.405-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:38.088-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.350-1.el5" test_ref="oval:org.mitre.oval:tst:141011"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.350-1.el6" test_ref="oval:org.mitre.oval:tst:113518"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24433" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0536: mysql55-mysql security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>mysql55-mysql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0536-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0536.html"/>
        <reference source="CESA" ref_id="CESA-2014:0536"/>
        <reference source="CVE" ref_id="CVE-2014-0384" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0384.html"/>
        <reference source="CVE" ref_id="CVE-2014-2419" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2419.html"/>
        <reference source="CVE" ref_id="CVE-2014-2430" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2430.html"/>
        <reference source="CVE" ref_id="CVE-2014-2431" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2431.html"/>
        <reference source="CVE" ref_id="CVE-2014-2432" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2432.html"/>
        <reference source="CVE" ref_id="CVE-2014-2436" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2436.html"/>
        <reference source="CVE" ref_id="CVE-2014-2438" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2438.html"/>
        <reference source="CVE" ref_id="CVE-2014-2440" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2440.html"/>
        <description>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

This update fixes several vulnerabilities in the MySQL database server.
Information about these flaws can be found on the Oracle Critical Patch
Update Advisory page, listed in the References section. (CVE-2014-2436,
CVE-2014-2440, CVE-2014-0384, CVE-2014-2419, CVE-2014-2430, CVE-2014-2431,
CVE-2014-2432, CVE-2014-2438)

These updated packages upgrade MySQL to version 5.5.37. Refer to the MySQL
Release Notes listed in the References section for a complete list of
changes.

All MySQL users should upgrade to these updated packages, which correct
these issues. After installing this update, the MySQL server daemon
(mysqld) will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-09T15:16:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-06-10T14:50:18.716-04:00">DRAFT</status_change>
            <status_change date="2014-06-30T04:10:17.091-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:18.432-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mysql55-mysql-test is earlier than 0:5.5.37-1.el5" test_ref="oval:org.mitre.oval:tst:114420"/>
          <criterion comment="mysql55-mysql-libs is earlier than 0:5.5.37-1.el5" test_ref="oval:org.mitre.oval:tst:114763"/>
          <criterion comment="mysql55-mysql is earlier than 0:5.5.37-1.el5" test_ref="oval:org.mitre.oval:tst:114695"/>
          <criterion comment="mysql55-mysql-devel is earlier than 0:5.5.37-1.el5" test_ref="oval:org.mitre.oval:tst:114436"/>
          <criterion comment="mysql55-mysql-bench is earlier than 0:5.5.37-1.el5" test_ref="oval:org.mitre.oval:tst:114858"/>
          <criterion comment="mysql55-mysql-server is earlier than 0:5.5.37-1.el5" test_ref="oval:org.mitre.oval:tst:114777"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24378" version="47" class="patch">
      <metadata>
        <title>RHSA-2014:0341: wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0341-01" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0341.html"/>
        <reference source="CESA" ref_id="CESA-2014:0341"/>
        <reference source="CVE" ref_id="CVE-2012-5595" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5595.html"/>
        <reference source="CVE" ref_id="CVE-2012-5598" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5598.html"/>
        <reference source="CVE" ref_id="CVE-2012-5599" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5599.html"/>
        <reference source="CVE" ref_id="CVE-2012-5600" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5600.html"/>
        <reference source="CVE" ref_id="CVE-2012-6056" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6056.html"/>
        <reference source="CVE" ref_id="CVE-2012-6060" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6060.html"/>
        <reference source="CVE" ref_id="CVE-2012-6061" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6061.html"/>
        <reference source="CVE" ref_id="CVE-2012-6062" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6062.html"/>
        <reference source="CVE" ref_id="CVE-2013-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3557.html"/>
        <reference source="CVE" ref_id="CVE-2013-3559" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3559.html"/>
        <reference source="CVE" ref_id="CVE-2013-4081" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4081.html"/>
        <reference source="CVE" ref_id="CVE-2013-4083" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4083.html"/>
        <reference source="CVE" ref_id="CVE-2013-4927" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4927.html"/>
        <reference source="CVE" ref_id="CVE-2013-4931" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4931.html"/>
        <reference source="CVE" ref_id="CVE-2013-4932" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4932.html"/>
        <reference source="CVE" ref_id="CVE-2013-4933" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4933.html"/>
        <reference source="CVE" ref_id="CVE-2013-4934" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4934.html"/>
        <reference source="CVE" ref_id="CVE-2013-4935" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4935.html"/>
        <reference source="CVE" ref_id="CVE-2013-5721" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5721.html"/>
        <reference source="CVE" ref_id="CVE-2013-7112" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-7112.html"/>
        <reference source="CVE" ref_id="CVE-2014-2281" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2281.html"/>
        <reference source="CVE" ref_id="CVE-2014-2299" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2299.html"/>
        <description>Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large record in MPEG data.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-02T11:44:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-03T10:28:23.539-04:00">DRAFT</status_change>
            <status_change date="2014-04-21T04:00:49.588-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:50.608-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="wireshark-gnome is earlier than 0:1.0.15-6.el5_10" test_ref="oval:org.mitre.oval:tst:112967"/>
          <criterion comment="wireshark is earlier than 0:1.0.15-6.el5_10" test_ref="oval:org.mitre.oval:tst:113019"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24340" version="6" class="patch">
      <metadata>
        <title>RHSA-2014:0348: xalan-j2 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>xalan-j2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0348-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0348.html"/>
        <reference source="CESA" ref_id="CESA-2014:0348"/>
        <reference source="CVE" ref_id="CVE-2014-0107" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0107.html"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-02T11:44:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-03T10:28:23.096-04:00">DRAFT</status_change>
            <status_change date="2014-04-21T04:00:45.803-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:47.975-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24340 - 3 patches on RHEL where CentOS checks were added" date="2014-07-28T18:10:00.421-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:11:31.352-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:30.309-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xalan-j2-demo is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:112937"/>
            <criterion comment="xalan-j2-manual is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:112887"/>
            <criterion comment="xalan-j2-javadoc is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:112942"/>
            <criterion comment="xalan-j2-xsltc is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:112612"/>
            <criterion comment="xalan-j2 is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:113186"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xalan-j2-demo is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113365"/>
            <criterion comment="xalan-j2-manual is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113217"/>
            <criterion comment="xalan-j2-xsltc is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113295"/>
            <criterion comment="xalan-j2-javadoc is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113337"/>
            <criterion comment="xalan-j2 is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113048"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24327" version="7" class="patch">
      <metadata>
        <title>RHSA-2014:0206: openldap security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openldap</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0206-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0206.html"/>
        <reference source="CESA" ref_id="CESA-2014:0206"/>
        <reference source="CVE" ref_id="CVE-2013-4449" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4449.html"/>
        <description>The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which triggers rwm_conn_destroy to free the session context while it is being used by rwm_op_search.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-07T13:03:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-03-21T13:20:47.157-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:54.042-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24327 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:36:00.515-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:47.086-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24327 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:36.681-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:11.765-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openldap-devel is earlier than 0:2.3.43-27.el5_10" test_ref="oval:org.mitre.oval:tst:111982"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.3.43-27.el5_10" test_ref="oval:org.mitre.oval:tst:112637"/>
          <criterion comment="openldap-clients is earlier than 0:2.3.43-27.el5_10" test_ref="oval:org.mitre.oval:tst:112886"/>
          <criterion comment="openldap-servers is earlier than 0:2.3.43-27.el5_10" test_ref="oval:org.mitre.oval:tst:112970"/>
          <criterion comment="openldap-servers-overlays is earlier than 0:2.3.43-27.el5_10" test_ref="oval:org.mitre.oval:tst:112755"/>
          <criterion comment="compat-openldap is earlier than 0:2.3.43_2.2.29-27.el5_10" test_ref="oval:org.mitre.oval:tst:112766"/>
          <criterion comment="openldap is earlier than 0:2.3.43-27.el5_10" test_ref="oval:org.mitre.oval:tst:112530"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24293" version="27" class="patch">
      <metadata>
        <title>RHSA-2014:0310: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0310-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0310.html"/>
        <reference source="CESA" ref_id="CESA-2014:0310"/>
        <reference source="CVE" ref_id="CVE-2014-1493" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1493.html"/>
        <reference source="CVE" ref_id="CVE-2014-1497" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1497.html"/>
        <reference source="CVE" ref_id="CVE-2014-1505" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1505.html"/>
        <reference source="CVE" ref_id="CVE-2014-1508" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1508.html"/>
        <reference source="CVE" ref_id="CVE-2014-1509" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1509.html"/>
        <reference source="CVE" ref_id="CVE-2014-1510" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1510.html"/>
        <reference source="CVE" ref_id="CVE-2014-1511" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1511.html"/>
        <reference source="CVE" ref_id="CVE-2014-1512" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1512.html"/>
        <reference source="CVE" ref_id="CVE-2014-1513" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1513.html"/>
        <reference source="CVE" ref_id="CVE-2014-1514" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1514.html"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1493, CVE-2014-1510, CVE-2014-1511, CVE-2014-1512,
CVE-2014-1513, CVE-2014-1514)

Several information disclosure flaws were found in the way Firefox
processed malformed web content. An attacker could use these flaws to gain
access to sensitive information such as cross-domain content or protected
memory addresses or, potentially, cause Firefox to crash. (CVE-2014-1497,
CVE-2014-1508, CVE-2014-1505)

A memory corruption flaw was found in the way Firefox rendered certain PDF
files. An attacker able to trick a user into installing a malicious
extension could use this flaw to crash Firefox or, potentially, execute
arbitrary code with the privileges of the user running Firefox.
(CVE-2014-1509)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Benoit Jacob, Olli Pettay, Jan Varga, Jan de Mooij,
Jesse Ruderman, Dan Gohman, Christoph Diehl, Atte Kettunen, Tyson Smith,
Jesse Schwartzentruber, John Thomson, Robert O'Callahan, Mariusz Mlynski,
Jüri Aedla, George Hotz, and the security research firm VUPEN as the
original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.4.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 24.4.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-24T12:19:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-01T10:03:33.713-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24293 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:32:00.818-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:44.438-04:00">INTERIM</status_change>
            <status_change date="2014-06-02T04:00:10.760-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24293 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:37.186-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:09.689-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:24.4.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:112878"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="firefox is earlier than 0:24.4.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:113033"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:24.4.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:113576"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="firefox is earlier than 0:24.4.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:113902"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24262" version="4" class="patch">
      <metadata>
        <title>RHSA-2014:0741: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0741-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0741.html"/>
        <reference source="CESA" ref_id="CESA-2014:0741"/>
        <reference source="CVE" ref_id="CVE-2014-1533" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1533.html"/>
        <reference source="CVE" ref_id="CVE-2014-1538" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1538.html"/>
        <reference source="CVE" ref_id="CVE-2014-1541" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1541.html"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1533, CVE-2014-1538, CVE-2014-1541)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Christoph Diehl, Christian Holler, Hannes
Verschore, Jan de Mooij, Ryan VanderMeulen, Jeff Walden, Kyle Huey,
Abhishek Arya, and Nils as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.6.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 24.6.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-02T17:22:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-07T16:13:32.348-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:17.168-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24262 - 3 patches on RHEL where CentOS checks were added" date="2014-07-28T18:10:00.421-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-18T04:02:29.438-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:24.6.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:115278"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:24.6.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:115251"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="firefox is earlier than 0:24.6.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:114950"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="firefox is earlier than 0:24.6.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:114602"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria comment="Redhat 7 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:24.6.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:115498"/>
            <criterion comment="xulrunner-devel is earlier than 0:24.6.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:115120"/>
            <criterion comment="xulrunner is earlier than 0:24.6.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:115439"/>
          </criteria>
        </criteria>
        <criteria comment="Centos 7 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:24.6.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:116069"/>
            <criterion comment="xulrunner is earlier than 0:24.6.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:115672"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24953" version="3" class="inventory">
      <metadata>
        <title>The operating system installed on the system is Red Hat Enterprise Linux 7</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 7</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:redhat:enterprise_linux:7"/>
        <description>The operating system installed on the system is Red Hat Enterprise Linux 7.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-02T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-07-07T16:13:29.153-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:42.013-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:58.393-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Red Hat Enterprise 7 is installed" test_ref="oval:org.mitre.oval:tst:115398"/>
        <criterion negate="true" comment="Oracle Linux 7.x is installed" test_ref="oval:org.mitre.oval:tst:115342"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24773" version="3" class="inventory">
      <metadata>
        <title>The operating system installed on the system is CentOS Linux 7.x</title>
        <affected family="unix">
          <platform>CentOS Linux 7</platform>
        </affected>
        <reference ref_id="cpe:/o:centos:centos:7" source="CPE"/>
        <description>The operating system installed on the system is CentOS Linux 7.x</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-08T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-07-09T11:48:47.285-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:27.738-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:46.796-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Unix family" test_ref="oval:org.mitre.oval:tst:4424"/>
        <criterion comment="CentOS Linux 7.x is installed" test_ref="oval:org.mitre.oval:tst:115369"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24260" version="7" class="patch">
      <metadata>
        <title>RHSA-2014:0330: samba and samba3x security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0330-01" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0330.html"/>
        <reference source="CESA" ref_id="CESA-2014:0330"/>
        <reference source="CVE" ref_id="CVE-2012-6150" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6150.html"/>
        <reference source="CVE" ref_id="CVE-2013-4496" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4496.html"/>
        <description>Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obtain access via brute-force ChangePasswordUser2 (1) SAMR or (2) RAP attempts.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-02T11:44:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-03T10:28:24.911-04:00">DRAFT</status_change>
            <status_change date="2014-04-21T04:00:41.476-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:42.395-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:112514"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:112992"/>
            <criterion comment="samba3x is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113193"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113084"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113155"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113272"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113128"/>
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113304"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba-swat is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:112639"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:112379"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:112720"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:112784"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:112354"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113240"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113361"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113289"/>
            <criterion comment="samba is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113058"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:112481"/>
            <criterion comment="samba-common is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:112759"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113037"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24254" version="21" class="patch">
      <metadata>
        <title>RHSA-2014:0285: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0285-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0285.html"/>
        <reference source="CESA" ref_id="CESA-2014:0285"/>
        <reference source="CVE" ref_id="CVE-2013-2929" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2929.html"/>
        <reference source="CVE" ref_id="CVE-2013-4483" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4483.html"/>
        <reference source="CVE" ref_id="CVE-2013-4554" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4554.html"/>
        <reference source="CVE" ref_id="CVE-2013-6381" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6381.html"/>
        <reference source="CVE" ref_id="CVE-2013-6383" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6383.html"/>
        <reference source="CVE" ref_id="CVE-2013-6885" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6885.html"/>
        <reference source="CVE" ref_id="CVE-2013-7263" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-7263.html"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A buffer overflow flaw was found in the way the qeth_snmp_command()
function in the Linux kernel's QETH network device driver implementation
handled SNMP IOCTL requests with an out-of-bounds length. A local,
unprivileged user could use this flaw to crash the system or, potentially,
escalate their privileges on the system. (CVE-2013-6381, Important)

* A flaw was found in the way the ipc_rcu_putref() function in the Linux
kernel's IPC implementation handled reference counter decrementing.
A local, unprivileged user could use this flaw to trigger an Out of Memory
(OOM) condition and, potentially, crash the system. (CVE-2013-4483,
Moderate)

* It was found that the Xen hypervisor implementation did not correctly
check privileges of hypercall attempts made by HVM guests, allowing
hypercalls to be invoked from protection rings 1 and 2 in addition to ring
0. A local attacker in an HVM guest able to execute code on privilege
levels 1 and 2 could potentially use this flaw to further escalate their
privileges in that guest. Note: Xen HVM guests running unmodified versions
of Red Hat Enterprise Linux and Microsoft Windows are not affected by this
issue because they are known to only use protection rings 0 (kernel) and 3
(userspace). (CVE-2013-4554, Moderate)

* A flaw was found in the way the Linux kernel's Adaptec RAID controller
(aacraid) checked permissions of compat IOCTLs. A local attacker could use
this flaw to bypass intended security restrictions. (CVE-2013-6383,
Moderate)

* It was found that, under specific circumstances, a combination of write
operations to write-combined memory and locked CPU instructions may cause a
core hang on certain AMD CPUs (for more information, refer to AMD CPU
erratum 793 linked in the References section). A privileged user in a guest
running under the Xen hypervisor could use this flaw to cause a denial of
service on the host system. This update adds a workaround to the Xen
hypervisor implementation, which mitigates the AMD CPU issue. Note: this
issue only affects AMD Family 16h Models 00h-0Fh Processors. Non-AMD CPUs
are not vulnerable. (CVE-2013-6885, Moderate)

* It was found that certain protocol handlers in the Linux kernel's
networking implementation could set the addr_len value without initializing
the associated data structure. A local, unprivileged user could use this
flaw to leak kernel stack memory to user space using the recvmsg, recvfrom,
and recvmmsg system calls. (CVE-2013-7263, Low)

* A flaw was found in the way the get_dumpable() function return value was
interpreted in the ptrace subsystem of the Linux kernel. When
'fs.suid_dumpable' was set to 2, a local, unprivileged local user could
use this flaw to bypass intended ptrace restrictions and obtain
potentially sensitive information. (CVE-2013-2929, Low)

Red Hat would like to thank Vladimir Davydov of Parallels for reporting
CVE-2013-4483 and the Xen project for reporting CVE-2013-4554 and
CVE-2013-6885. Upstream acknowledges Jan Beulich as the original reporter
of CVE-2013-4554 and CVE-2013-6885.

This update also fixes several bugs and adds one enhancement.
Documentation for these changes will be available shortly from the
Technical Notes document linked to in the References section.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add this
enhancement. The system must be rebooted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-24T12:19:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-01T10:03:33.155-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24254 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:32:00.818-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:41.786-04:00">INTERIM</status_change>
            <status_change date="2014-06-02T04:00:10.214-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24254 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:36.469-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:08.495-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:113167"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:113211"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:113143"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:113114"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:113236"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:112986"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:113138"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:112804"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:113042"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:112592"/>
          <criterion comment="kernel is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:112921"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:113100"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24237" version="8" class="patch">
      <metadata>
        <title>RHSA-2014:0266: sudo security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0266-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0266.html"/>
        <reference source="CESA" ref_id="CESA-2014:0266"/>
        <reference source="CVE" ref_id="CVE-2014-0106" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0106.html"/>
        <description>The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root.

A flaw was found in the way sudo handled its blacklist of environment
variables. When the "env_reset" option was disabled, a user permitted to
run certain commands via sudo could use this flaw to run such a command
with one of the blacklisted environment variables set, allowing them to run
an arbitrary command with the target user's privileges. (CVE-2014-0106)

Note: This issue does not affect the default configuration of the sudo
package as shipped with Red Hat Enterprise Linux 5.

Red Hat would like to thank Todd C. Miller for reporting this issue.
Upstream acknowledges Sebastien Macke as the original reporter.

All sudo users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-24T12:19:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-01T10:03:31.979-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24237 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:32:00.818-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:40.659-04:00">INTERIM</status_change>
            <status_change date="2014-06-02T04:00:09.667-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24237 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:37.484-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:07.949-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="sudo is earlier than 0:1.7.2p1-29.el5_10" test_ref="oval:org.mitre.oval:tst:113028"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24230" version="21" class="patch">
      <metadata>
        <title>RHSA-2014:0249: postgresql security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0249-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0249.html"/>
        <reference source="CESA" ref_id="CESA-2014:0249"/>
        <reference source="CVE" ref_id="CVE-2014-0060" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0060.html"/>
        <reference source="CVE" ref_id="CVE-2014-0061" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0061.html"/>
        <reference source="CVE" ref_id="CVE-2014-0062" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0062.html"/>
        <reference source="CVE" ref_id="CVE-2014-0063" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0063.html"/>
        <reference source="CVE" ref_id="CVE-2014-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0064.html"/>
        <reference source="CVE" ref_id="CVE-2014-0065" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0065.html"/>
        <reference source="CVE" ref_id="CVE-2014-0066" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0066.html"/>
        <description>PostgreSQL is an advanced object-relational database management system
(DBMS).

Multiple stack-based buffer overflow flaws were found in the date/time
implementation of PostgreSQL. An authenticated database user could provide
a specially crafted date/time value that, when processed, could cause
PostgreSQL to crash or, potentially, execute arbitrary code with the
permissions of the user running PostgreSQL. (CVE-2014-0063)

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in various type input functions in PostgreSQL. An authenticated
database user could possibly use these flaws to crash PostgreSQL or,
potentially, execute arbitrary code with the permissions of the user
running PostgreSQL. (CVE-2014-0064)

Multiple potential buffer overflow flaws were found in PostgreSQL.
An authenticated database user could possibly use these flaws to crash
PostgreSQL or, potentially, execute arbitrary code with the permissions of
the user running PostgreSQL. (CVE-2014-0065)

It was found that granting an SQL role to a database user in a PostgreSQL
database without specifying the "ADMIN" option allowed the grantee to
remove other users from their granted role. An authenticated database user
could use this flaw to remove a user from an SQL role which they were
granted access to. (CVE-2014-0060)

A flaw was found in the validator functions provided by PostgreSQL's
procedural languages (PLs). An authenticated database user could possibly
use this flaw to escalate their privileges. (CVE-2014-0061)

A race condition was found in the way the CREATE INDEX command performed
multiple independent lookups of a table that had to be indexed. An
authenticated database user could possibly use this flaw to escalate their
privileges. (CVE-2014-0062)

It was found that the chkpass extension of PostgreSQL did not check the
return value of the crypt() function. An authenticated database user could
possibly use this flaw to crash PostgreSQL via a null pointer dereference.
(CVE-2014-0066)

Red Hat would like to thank the PostgreSQL project for reporting these
issues. Upstream acknowledges Noah Misch as the original reporter of
CVE-2014-0060 and CVE-2014-0063, Heikki Linnakangas and Noah Misch as the
original reporters of CVE-2014-0064, Peter Eisentraut and Jozef Mlich as
the original reporters of CVE-2014-0065, Andres Freund as the original
reporter of CVE-2014-0061, Robert Haas and Andres Freund as the original
reporters of CVE-2014-0062, and Honza Horak and Bruce Momjian as the
original reporters of CVE-2014-0066.

These updated packages upgrade PostgreSQL to version 8.4.20, which fixes
these issues as well as several non-security issues. Refer to the
PostgreSQL Release Notes for a full list of changes:

http://www.postgresql.org/docs/8.4/static/release-8-4-19.html
http://www.postgresql.org/docs/8.4/static/release-8-4-20.html

All PostgreSQL users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. If the postgresql
service is running, it will be automatically restarted after installing
this update.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-07T13:03:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-03-21T13:20:47.931-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:53.175-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24230 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:36:00.515-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:39.784-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24230 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:37.918-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:07.379-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="postgresql-contrib is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:112961"/>
          <criterion comment="postgresql-docs is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:112708"/>
          <criterion comment="postgresql-devel is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:112414"/>
          <criterion comment="postgresql is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:112345"/>
          <criterion comment="postgresql-test is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:112385"/>
          <criterion comment="postgresql-pl is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:112732"/>
          <criterion comment="postgresql-python is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:112729"/>
          <criterion comment="postgresql-tcl is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:112966"/>
          <criterion comment="postgresql-server is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:112894"/>
          <criterion comment="postgresql-libs is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:112293"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24204" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0740: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0740-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0740.html"/>
        <reference source="CESA" ref_id="CESA-2014:0740"/>
        <reference source="CVE" ref_id="CVE-2013-7339" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-7339.html"/>
        <reference source="CVE" ref_id="CVE-2014-1737" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1737.html"/>
        <reference source="CVE" ref_id="CVE-2014-1738" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1738.html"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's floppy driver handled user
space provided data in certain error code paths while processing FDRAWCMD
IOCTL commands. A local user with write access to /dev/fdX could use this
flaw to free (using the kfree() function) arbitrary kernel memory.
(CVE-2014-1737, Important)

* It was found that the Linux kernel's floppy driver leaked internal kernel
memory addresses to user space during the processing of the FDRAWCMD IOCTL
command. A local user with write access to /dev/fdX could use this flaw to
obtain information about the kernel heap arrangement. (CVE-2014-1738, Low)

Note: A local user with write access to /dev/fdX could use these two flaws
(CVE-2014-1737 in combination with CVE-2014-1738) to escalate their
privileges on the system.

* A NULL pointer dereference flaw was found in the rds_ib_laddr_check()
function in the Linux kernel's implementation of Reliable Datagram Sockets
(RDS). A local, unprivileged user could use this flaw to crash the system.
(CVE-2013-7339, Moderate)

Red Hat would like to thank Matthew Daley for reporting CVE-2014-1737 and
CVE-2014-1738.

This update also fixes the following bugs:

* A bug in the futex system call could result in an overflow when passing
a very large positive timeout. As a consequence, the FUTEX_WAIT operation
did not work as intended and the system call was timing out immediately.
A backported patch fixes this bug by limiting very large positive timeouts
to the maximal supported value. (BZ#1091832)

* A new Linux Security Module (LSM) functionality related to the setrlimit
hooks should produce a warning message when used by a third party module
that could not cope with it. However, due to a programming error, the
kernel could print this warning message when a process was setting rlimits
for a different process, or if rlimits were modified by another than the
main thread even though there was no incompatible third party module. This
update fixes the relevant code and ensures that the kernel handles this
warning message correctly. (BZ#1092869)

* Previously, the kernel was unable to detect KVM on system boot if the
Hyper-V emulation was enabled. A patch has been applied to ensure that
both KVM and Hyper-V hypervisors are now correctly detected during system
boot. (BZ#1094152)

* A function in the RPC code responsible for verifying whether cached
credentials match the current process did not perform the check correctly.
The code checked only whether the groups in the current process
credentials appear in the same order as in the cached credentials but did
not ensure that no other groups are present in the cached credentials. As
a consequence, when accessing files in NFS mounts, a process with the same
UID and GID as the original process but with a non-matching group list
could have been granted an unauthorized access to a file, or under certain
circumstances, the process could have been wrongly prevented from
accessing the file. The incorrect test condition has been fixed and the
problem can no longer occur. (BZ#1095062)

* When being under heavy load, some Fibre Channel storage devices, such as
Hitachi and HP Open-V series, can send a logout (LOGO) message to the
host system. However, due to a bug in the lpfc driver, this could result
in a loss of active paths to the storage and the paths could not be
recovered without manual intervention. This update corrects the lpfc
driver to ensure automatic recovery of the lost paths to the storage in
this scenario. (BZ#1096061)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-02T17:22:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-07T16:13:33.610-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:15.470-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:27.921-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115409"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115444"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115399"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115445"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115145"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115436"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115440"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115450"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115349"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115344"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115462"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:114597"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24202" version="30" class="patch">
      <metadata>
        <title>RHSA-2014:0223: libtiff security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0223-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0223.html"/>
        <reference source="CESA" ref_id="CESA-2014:0223"/>
        <reference source="CVE" ref_id="CVE-2013-1960" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1960.html"/>
        <reference source="CVE" ref_id="CVE-2013-1961" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1961.html"/>
        <reference source="CVE" ref_id="CVE-2013-4231" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4231.html"/>
        <reference source="CVE" ref_id="CVE-2013-4232" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4232.html"/>
        <reference source="CVE" ref_id="CVE-2013-4243" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4243.html"/>
        <reference source="CVE" ref_id="CVE-2013-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4244.html"/>
        <description>The LZW decompressor in the gif2tiff tool in libtiff 4.0.3 and earlier allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a crafted GIF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-07T13:03:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-03-21T13:20:47.585-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:52.734-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24202 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:36:00.515-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:37.955-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24202 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:38.309-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:06.461-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libtiff is earlier than 0:3.8.2-19.el5_10" test_ref="oval:org.mitre.oval:tst:112798"/>
          <criterion comment="libtiff-devel is earlier than 0:3.8.2-19.el5_10" test_ref="oval:org.mitre.oval:tst:112885"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24189" version="54" class="patch">
      <metadata>
        <title>RHSA-2014:0186: mysql55-mysql security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>mysql55-mysql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0186-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0186.html"/>
        <reference source="CESA" ref_id="CESA-2014:0186"/>
        <reference source="CVE" ref_id="CVE-2013-3839" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3839.html"/>
        <reference source="CVE" ref_id="CVE-2013-5807" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5807.html"/>
        <reference source="CVE" ref_id="CVE-2013-5891" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5891.html"/>
        <reference source="CVE" ref_id="CVE-2013-5908" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5908.html"/>
        <reference source="CVE" ref_id="CVE-2014-0001" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0001.html"/>
        <reference source="CVE" ref_id="CVE-2014-0386" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0386.html"/>
        <reference source="CVE" ref_id="CVE-2014-0393" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0393.html"/>
        <reference source="CVE" ref_id="CVE-2014-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0401.html"/>
        <reference source="CVE" ref_id="CVE-2014-0402" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0402.html"/>
        <reference source="CVE" ref_id="CVE-2014-0412" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0412.html"/>
        <reference source="CVE" ref_id="CVE-2014-0420" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0420.html"/>
        <reference source="CVE" ref_id="CVE-2014-0437" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0437.html"/>
        <description>Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-07T13:03:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-03-21T13:20:52.072-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:52.056-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24189 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:36:00.515-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:36.607-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24189 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:40.635-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:05.697-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mysql55-mysql-server is earlier than 0:5.5.36-2.el5" test_ref="oval:org.mitre.oval:tst:112200"/>
          <criterion comment="mysql55-mysql-libs is earlier than 0:5.5.36-2.el5" test_ref="oval:org.mitre.oval:tst:112568"/>
          <criterion comment="mysql55-mysql-devel is earlier than 0:5.5.36-2.el5" test_ref="oval:org.mitre.oval:tst:112855"/>
          <criterion comment="mysql55-mysql-bench is earlier than 0:5.5.36-2.el5" test_ref="oval:org.mitre.oval:tst:112845"/>
          <criterion comment="mysql55-mysql-test is earlier than 0:5.5.36-2.el5" test_ref="oval:org.mitre.oval:tst:112751"/>
          <criterion comment="mysql55-mysql is earlier than 0:5.5.36-2.el5" test_ref="oval:org.mitre.oval:tst:112608"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24162" version="18" class="patch">
      <metadata>
        <title>RHSA-2014:0196: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0196-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0196.html"/>
        <reference source="CVE" ref_id="CVE-2014-0498" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0498.html"/>
        <reference source="CVE" ref_id="CVE-2014-0499" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0499.html"/>
        <reference source="CVE" ref_id="CVE-2014-0502" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0502.html"/>
        <description>Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK &amp; Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-07T13:03:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-03-21T13:20:48.730-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:49.317-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24162 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:36:00.515-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:35.401-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24162 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:40.626-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:36.760-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.341-1.el5" test_ref="oval:org.mitre.oval:tst:140799"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.341-1.el6" test_ref="oval:org.mitre.oval:tst:112925"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24155" version="7" class="patch">
      <metadata>
        <title>RHSA-2014:0185: openswan security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>openswan</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0185-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0185.html"/>
        <reference source="CESA" ref_id="CESA-2014:0185"/>
        <reference source="CVE" ref_id="CVE-2013-6466" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6466.html"/>
        <description>Openswan 2.6.39 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-07T13:03:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-03-21T13:20:48.395-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:48.909-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24155 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:36:00.515-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:34.853-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24155 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:40.060-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:05.121-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openswan-doc is earlier than 0:2.6.32-7.3.el5_10" test_ref="oval:org.mitre.oval:tst:112679"/>
            <criterion comment="openswan is earlier than 0:2.6.32-7.3.el5_10" test_ref="oval:org.mitre.oval:tst:112172"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openswan-doc is earlier than 0:2.6.32-27.2.el6_5" test_ref="oval:org.mitre.oval:tst:112726"/>
            <criterion comment="openswan is earlier than 0:2.6.32-27.2.el6_5" test_ref="oval:org.mitre.oval:tst:112948"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24127" version="21" class="patch">
      <metadata>
        <title>RHSA-2014:0211: postgresql84 and postgresql security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0211-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0211.html"/>
        <reference source="CESA" ref_id="CESA-2014:0211"/>
        <reference source="CVE" ref_id="CVE-2014-0060" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0060.html"/>
        <reference source="CVE" ref_id="CVE-2014-0061" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0061.html"/>
        <reference source="CVE" ref_id="CVE-2014-0062" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0062.html"/>
        <reference source="CVE" ref_id="CVE-2014-0063" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0063.html"/>
        <reference source="CVE" ref_id="CVE-2014-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0064.html"/>
        <reference source="CVE" ref_id="CVE-2014-0065" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0065.html"/>
        <reference source="CVE" ref_id="CVE-2014-0066" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0066.html"/>
        <description>PostgreSQL is an advanced object-relational database management system
(DBMS).

Multiple stack-based buffer overflow flaws were found in the date/time
implementation of PostgreSQL. An authenticated database user could provide
a specially crafted date/time value that, when processed, could cause
PostgreSQL to crash or, potentially, execute arbitrary code with the
permissions of the user running PostgreSQL. (CVE-2014-0063)

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in various type input functions in PostgreSQL. An authenticated
database user could possibly use these flaws to crash PostgreSQL or,
potentially, execute arbitrary code with the permissions of the user
running PostgreSQL. (CVE-2014-0064)

Multiple potential buffer overflow flaws were found in PostgreSQL.
An authenticated database user could possibly use these flaws to crash
PostgreSQL or, potentially, execute arbitrary code with the permissions of
the user running PostgreSQL. (CVE-2014-0065)

It was found that granting an SQL role to a database user in a PostgreSQL
database without specifying the "ADMIN" option allowed the grantee to
remove other users from their granted role. An authenticated database user
could use this flaw to remove a user from an SQL role which they were
granted access to. (CVE-2014-0060)

A flaw was found in the validator functions provided by PostgreSQL's
procedural languages (PLs). An authenticated database user could possibly
use this flaw to escalate their privileges. (CVE-2014-0061)

A race condition was found in the way the CREATE INDEX command performed
multiple independent lookups of a table that had to be indexed. An
authenticated database user could possibly use this flaw to escalate their
privileges. (CVE-2014-0062)

It was found that the chkpass extension of PostgreSQL did not check the
return value of the crypt() function. An authenticated database user could
possibly use this flaw to crash PostgreSQL via a null pointer dereference.
(CVE-2014-0066)

Red Hat would like to thank the PostgreSQL project for reporting these
issues. Upstream acknowledges Noah Misch as the original reporter of
CVE-2014-0060 and CVE-2014-0063, Heikki Linnakangas and Noah Misch as the
original reporters of CVE-2014-0064, Peter Eisentraut and Jozef Mlich as
the original reporters of CVE-2014-0065, Andres Freund as the original
reporter of CVE-2014-0061, Robert Haas and Andres Freund as the original
reporters of CVE-2014-0062, and Honza Horak and Bruce Momjian as the
original reporters of CVE-2014-0066.

These updated packages upgrade PostgreSQL to version 8.4.20, which fixes
these issues as well as several non-security issues. Refer to the
PostgreSQL Release Notes for a full list of changes:

http://www.postgresql.org/docs/8.4/static/release-8-4-19.html
http://www.postgresql.org/docs/8.4/static/release-8-4-20.html

All PostgreSQL users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. If the postgresql
service is running, it will be automatically restarted after installing
this update.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-07T13:03:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-03-21T13:20:50.989-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:47.290-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24127 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:36:00.515-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:33.401-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24127 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:39.152-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:02.851-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql84-python is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112803"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112698"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112714"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112684"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112347"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112782"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112800"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112943"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112658"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112909"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112076"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112596"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql-contrib is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112960"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112717"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112744"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112591"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112749"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112856"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112494"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112907"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112462"/>
            <criterion comment="postgresql is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112809"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24079" version="11" class="patch">
      <metadata>
        <title>RHSA-2014:0311: php security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0311-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0311.html"/>
        <reference source="CESA" ref_id="CESA-2014:0311"/>
        <reference source="CVE" ref_id="CVE-2006-7243" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7243.html"/>
        <reference source="CVE" ref_id="CVE-2009-0689" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0689.html"/>
        <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A buffer overflow flaw was found in the way PHP parsed floating point
numbers from their text representation. If a PHP application converted
untrusted input strings to numbers, an attacker able to provide such input
could cause the application to crash or, possibly, execute arbitrary code
with the privileges of the application. (CVE-2009-0689)

It was found that PHP did not properly handle file names with a NULL
character. A remote attacker could possibly use this flaw to make a PHP
script access unexpected files and bypass intended file system access
restrictions. (CVE-2006-7243)

All php users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-24T12:19:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-01T10:03:31.066-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24079 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:32:00.818-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:32.085-04:00">INTERIM</status_change>
            <status_change date="2014-06-02T04:00:08.482-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24079 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:39.500-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:01.854-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="php-devel is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113268"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113183"/>
          <criterion comment="php-bcmath is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:112899"/>
          <criterion comment="php-cli is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:112738"/>
          <criterion comment="php-gd is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113104"/>
          <criterion comment="php-xml is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113260"/>
          <criterion comment="php-mbstring is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113162"/>
          <criterion comment="php is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:112287"/>
          <criterion comment="php-pdo is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113198"/>
          <criterion comment="php-imap is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:112990"/>
          <criterion comment="php-pgsql is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113158"/>
          <criterion comment="php-ldap is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113180"/>
          <criterion comment="php-soap is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113066"/>
          <criterion comment="php-ncurses is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113163"/>
          <criterion comment="php-common is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:112734"/>
          <criterion comment="php-snmp is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113142"/>
          <criterion comment="php-dba is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:112715"/>
          <criterion comment="php-odbc is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113054"/>
          <criterion comment="php-mysql is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113250"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24049" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0626: openssl097a and openssl098e security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssl097a</product>
          <product>openssl098e</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0626-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0626.html"/>
        <reference source="CESA" ref_id="CESA-2014:0626"/>
        <reference source="CVE" ref_id="CVE-2014-0224" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0224.html"/>
        <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

It was found that OpenSSL clients and servers could be forced, via a
specially crafted handshake packet, to use weak keying material for
communication. A man-in-the-middle attacker could use this flaw to decrypt
and modify traffic between a client and a server. (CVE-2014-0224)

Note: In order to exploit this flaw, both the server and the client must be
using a vulnerable version of OpenSSL; the server must be using OpenSSL
version 1.0.1 and above, and the client must be using any version of
OpenSSL. For more information about this flaw, refer to:
https://access.redhat.com/site/articles/904433

Red Hat would like to thank the OpenSSL project for reporting this issue.
Upstream acknowledges KIKUCHI Masashi of Lepidum as the original reporter
of this issue.

All OpenSSL users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-09T15:16:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-06-10T14:50:19.504-04:00">DRAFT</status_change>
            <status_change date="2014-06-30T04:10:02.201-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:07.362-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="openssl097a is earlier than 0:0.9.7a-12.el5_10.1" test_ref="oval:org.mitre.oval:tst:114639"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="openssl098e is earlier than 0:0.9.8e-18.el6_5.2" test_ref="oval:org.mitre.oval:tst:114586"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23979" version="27" class="patch">
      <metadata>
        <title>RHSA-2014:0316: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0316-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0316.html"/>
        <reference source="CESA" ref_id="CESA-2014:0316"/>
        <reference source="CVE" ref_id="CVE-2014-1493" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1493.html"/>
        <reference source="CVE" ref_id="CVE-2014-1497" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1497.html"/>
        <reference source="CVE" ref_id="CVE-2014-1505" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1505.html"/>
        <reference source="CVE" ref_id="CVE-2014-1508" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1508.html"/>
        <reference source="CVE" ref_id="CVE-2014-1509" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1509.html"/>
        <reference source="CVE" ref_id="CVE-2014-1510" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1510.html"/>
        <reference source="CVE" ref_id="CVE-2014-1511" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1511.html"/>
        <reference source="CVE" ref_id="CVE-2014-1512" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1512.html"/>
        <reference source="CVE" ref_id="CVE-2014-1513" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1513.html"/>
        <reference source="CVE" ref_id="CVE-2014-1514" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1514.html"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1493, CVE-2014-1510, CVE-2014-1511, CVE-2014-1512,
CVE-2014-1513, CVE-2014-1514)

Several information disclosure flaws were found in the way Thunderbird
processed malformed web content. An attacker could use these flaws to gain
access to sensitive information such as cross-domain content or protected
memory addresses or, potentially, cause Thunderbird to crash.
(CVE-2014-1497, CVE-2014-1508, CVE-2014-1505)

A memory corruption flaw was found in the way Thunderbird rendered certain
PDF files. An attacker able to trick a user into installing a malicious
extension could use this flaw to crash Thunderbird or, potentially, execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2014-1509)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Benoit Jacob, Olli Pettay, Jan Varga, Jan de Mooij,
Jesse Ruderman, Dan Gohman, Christoph Diehl, Atte Kettunen, Tyson Smith,
Jesse Schwartzentruber, John Thomson, Robert O'Callahan, Mariusz Mlynski,
Jüri Aedla, George Hotz, and the security research firm VUPEN as the
original reporters of these issues.

Note: All of the above issues cannot be exploited by a specially-crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.4.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.4.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-24T12:19:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-01T10:03:32.220-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23979 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:32:00.818-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:28.888-04:00">INTERIM</status_change>
            <status_change date="2014-06-02T04:00:07.380-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23979 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:38.130-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:59.314-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:112930"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:112746"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:113786"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:113625"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23928" version="9" class="patch">
      <metadata>
        <title>RHSA-2014:0289: flash-plugin security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0289-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0289.html"/>
        <reference source="CVE" ref_id="CVE-2014-0503" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0503.html"/>
        <reference source="CVE" ref_id="CVE-2014-0504" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0504.html"/>
        <description>Adobe Flash Player before 11.7.700.272 and 11.8.x through 12.0.x before 12.0.0.77 on Windows and OS X, and before 11.2.202.346 on Linux, allows attackers to read the clipboard via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-24T12:19:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-01T10:03:32.590-04:00">DRAFT</status_change>
            <status_change date="2014-04-21T04:00:33.254-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:27.977-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23928 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:39.342-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:35.253-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.346-1.el5" test_ref="oval:org.mitre.oval:tst:140987"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.346-1.el6" test_ref="oval:org.mitre.oval:tst:112587"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23918" version="14" class="patch">
      <metadata>
        <title>RHSA-2014:0247: gnutls security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0247-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0247.html"/>
        <reference source="CESA" ref_id="CESA-2014:0247"/>
        <reference source="CVE" ref_id="CVE-2009-5138" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-5138.html"/>
        <reference source="CVE" ref_id="CVE-2014-0092" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0092.html"/>
        <description>lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-07T13:03:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-03-21T13:20:49.227-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:27.454-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23918 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:36:00.515-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:27.727-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23918 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:35.860-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:59.033-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="gnutls-devel is earlier than 0:1.4.1-14.el5_10" test_ref="oval:org.mitre.oval:tst:112053"/>
          <criterion comment="gnutls-utils is earlier than 0:1.4.1-14.el5_10" test_ref="oval:org.mitre.oval:tst:112703"/>
          <criterion comment="gnutls is earlier than 0:1.4.1-14.el5_10" test_ref="oval:org.mitre.oval:tst:112944"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23890" version="7" class="patch">
      <metadata>
        <title>RHSA-2014:0322: net-snmp security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>net-snmp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0322-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0322.html"/>
        <reference source="CESA" ref_id="CESA-2014:0322"/>
        <reference source="CVE" ref_id="CVE-2012-6151" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6151.html"/>
        <reference source="CVE" ref_id="CVE-2014-2285" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2285.html"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-02T11:44:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-03T10:28:26.808-04:00">DRAFT</status_change>
            <status_change date="2014-04-21T04:00:32.814-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:26.798-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="net-snmp-perl is earlier than 1:5.3.2.2-22.el5_10.1" test_ref="oval:org.mitre.oval:tst:113215"/>
          <criterion comment="net-snmp-utils is earlier than 1:5.3.2.2-22.el5_10.1" test_ref="oval:org.mitre.oval:tst:112340"/>
          <criterion comment="net-snmp-devel is earlier than 1:5.3.2.2-22.el5_10.1" test_ref="oval:org.mitre.oval:tst:112801"/>
          <criterion comment="net-snmp-libs is earlier than 1:5.3.2.2-22.el5_10.1" test_ref="oval:org.mitre.oval:tst:113112"/>
          <criterion comment="net-snmp is earlier than 1:5.3.2.2-22.el5_10.1" test_ref="oval:org.mitre.oval:tst:113082"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23870" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0486: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0486-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0486.html"/>
        <reference source="CVE" ref_id="CVE-2013-6629" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6629.html"/>
        <reference source="CVE" ref_id="CVE-2013-6954" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6954.html"/>
        <reference source="CVE" ref_id="CVE-2014-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0429.html"/>
        <reference source="CVE" ref_id="CVE-2014-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0446.html"/>
        <reference source="CVE" ref_id="CVE-2014-0448" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0448.html"/>
        <reference source="CVE" ref_id="CVE-2014-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0449.html"/>
        <reference source="CVE" ref_id="CVE-2014-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0451.html"/>
        <reference source="CVE" ref_id="CVE-2014-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0452.html"/>
        <reference source="CVE" ref_id="CVE-2014-0453" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0453.html"/>
        <reference source="CVE" ref_id="CVE-2014-0454" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0454.html"/>
        <reference source="CVE" ref_id="CVE-2014-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0455.html"/>
        <reference source="CVE" ref_id="CVE-2014-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0457.html"/>
        <reference source="CVE" ref_id="CVE-2014-0458" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0458.html"/>
        <reference source="CVE" ref_id="CVE-2014-0459" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0459.html"/>
        <reference source="CVE" ref_id="CVE-2014-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0460.html"/>
        <reference source="CVE" ref_id="CVE-2014-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0461.html"/>
        <reference source="CVE" ref_id="CVE-2014-1876" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1876.html"/>
        <reference source="CVE" ref_id="CVE-2014-2398" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2398.html"/>
        <reference source="CVE" ref_id="CVE-2014-2401" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2401.html"/>
        <reference source="CVE" ref_id="CVE-2014-2402" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2402.html"/>
        <reference source="CVE" ref_id="CVE-2014-2409" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2409.html"/>
        <reference source="CVE" ref_id="CVE-2014-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2412.html"/>
        <reference source="CVE" ref_id="CVE-2014-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2414.html"/>
        <reference source="CVE" ref_id="CVE-2014-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2420.html"/>
        <reference source="CVE" ref_id="CVE-2014-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2421.html"/>
        <reference source="CVE" ref_id="CVE-2014-2423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2423.html"/>
        <reference source="CVE" ref_id="CVE-2014-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2427.html"/>
        <reference source="CVE" ref_id="CVE-2014-2428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2428.html"/>
        <description>IBM Java SE version 7 includes the IBM Java Runtime Environment and the IBM
Java Software Development Kit.

This update fixes several vulnerabilities in the IBM Java Runtime
Environment and the IBM Java Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM Security alerts
page, listed in the References section. (CVE-2014-0457, CVE-2014-2421,
CVE-2014-0429, CVE-2014-0461, CVE-2014-0455, CVE-2014-2428, CVE-2014-0448,
CVE-2014-0454, CVE-2014-0446, CVE-2014-0452, CVE-2014-0451, CVE-2014-2402,
CVE-2014-2423, CVE-2014-2427, CVE-2014-0458, CVE-2014-2414, CVE-2014-2412,
CVE-2014-2409, CVE-2014-0460, CVE-2013-6954, CVE-2013-6629, CVE-2014-2401,
CVE-2014-0449, CVE-2014-0459, CVE-2014-0453, CVE-2014-2398, CVE-2014-1876,
CVE-2014-2420)

All users of java-1.7.0-ibm are advised to upgrade to these updated
packages, containing the IBM Java SE 7 SR7 release. All running instances
of IBM Java must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-21T16:07:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-05-23T10:29:10.975-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:21.032-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:56.645-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114142"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114099"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114375"/>
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114105"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114196"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:113910"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114180"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113583"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113637"/>
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114182"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114034"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114263"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23548" version="13" class="patch">
      <metadata>
        <title>RHSA-2014:0305: samba security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0305-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0305.html"/>
        <reference source="CESA" ref_id="CESA-2014:0305"/>
        <reference source="CVE" ref_id="CVE-2013-0213" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0213.html"/>
        <reference source="CVE" ref_id="CVE-2013-0214" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0214.html"/>
        <reference source="CVE" ref_id="CVE-2013-4124" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4124.html"/>
        <description>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

It was discovered that the Samba Web Administration Tool (SWAT) did not
protect against being opened in a web page frame. A remote attacker could
possibly use this flaw to conduct a clickjacking attack against SWAT users
or users with an active SWAT session. (CVE-2013-0213)

A flaw was found in the Cross-Site Request Forgery (CSRF) protection
mechanism implemented in SWAT. An attacker with the knowledge of a victim's
password could use this flaw to bypass CSRF protections and conduct a CSRF
attack against the victim SWAT user. (CVE-2013-0214)

An integer overflow flaw was found in the way Samba handled an Extended
Attribute (EA) list provided by a client. A malicious client could send a
specially crafted EA list that triggered an overflow, causing the server to
loop and reprocess the list using an excessive amount of memory.
(CVE-2013-4124)

Note: This issue did not affect the default configuration of the Samba
server.

Red Hat would like to thank the Samba project for reporting CVE-2013-0213
and CVE-2013-0214. Upstream acknowledges Jann Horn as the original reporter
of CVE-2013-0213 and CVE-2013-0214.

All users of Samba are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-24T12:19:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-01T10:03:32.818-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23548 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:32:00.818-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:23.987-04:00">INTERIM</status_change>
            <status_change date="2014-06-02T04:00:05.968-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23548 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:35.314-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:58.122-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="samba-swat is earlier than 0:3.0.33-3.40.el5_10" test_ref="oval:org.mitre.oval:tst:112868"/>
          <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.40.el5_10" test_ref="oval:org.mitre.oval:tst:113015"/>
          <criterion comment="libsmbclient is earlier than 0:3.0.33-3.40.el5_10" test_ref="oval:org.mitre.oval:tst:112977"/>
          <criterion comment="samba-client is earlier than 0:3.0.33-3.40.el5_10" test_ref="oval:org.mitre.oval:tst:113212"/>
          <criterion comment="samba is earlier than 0:3.0.33-3.40.el5_10" test_ref="oval:org.mitre.oval:tst:113154"/>
          <criterion comment="samba-common is earlier than 0:3.0.33-3.40.el5_10" test_ref="oval:org.mitre.oval:tst:113242"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22560" version="207" class="patch">
      <metadata>
        <title>RHSA-2014:0135: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0135-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0135.html"/>
        <reference source="CVE" ref_id="CVE-2013-5878" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5878.html"/>
        <reference source="CVE" ref_id="CVE-2013-5884" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5884.html"/>
        <reference source="CVE" ref_id="CVE-2013-5887" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5887.html"/>
        <reference source="CVE" ref_id="CVE-2013-5888" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5888.html"/>
        <reference source="CVE" ref_id="CVE-2013-5889" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5889.html"/>
        <reference source="CVE" ref_id="CVE-2013-5896" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5896.html"/>
        <reference source="CVE" ref_id="CVE-2013-5898" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5898.html"/>
        <reference source="CVE" ref_id="CVE-2013-5899" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5899.html"/>
        <reference source="CVE" ref_id="CVE-2013-5907" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5907.html"/>
        <reference source="CVE" ref_id="CVE-2013-5910" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5910.html"/>
        <reference source="CVE" ref_id="CVE-2014-0368" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0368.html"/>
        <reference source="CVE" ref_id="CVE-2014-0373" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0373.html"/>
        <reference source="CVE" ref_id="CVE-2014-0375" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0375.html"/>
        <reference source="CVE" ref_id="CVE-2014-0376" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0376.html"/>
        <reference source="CVE" ref_id="CVE-2014-0387" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0387.html"/>
        <reference source="CVE" ref_id="CVE-2014-0403" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0403.html"/>
        <reference source="CVE" ref_id="CVE-2014-0410" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0410.html"/>
        <reference source="CVE" ref_id="CVE-2014-0411" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0411.html"/>
        <reference source="CVE" ref_id="CVE-2014-0415" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0415.html"/>
        <reference source="CVE" ref_id="CVE-2014-0416" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0416.html"/>
        <reference source="CVE" ref_id="CVE-2014-0417" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0417.html"/>
        <reference source="CVE" ref_id="CVE-2014-0422" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0422.html"/>
        <reference source="CVE" ref_id="CVE-2014-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0423.html"/>
        <reference source="CVE" ref_id="CVE-2014-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0424.html"/>
        <reference source="CVE" ref_id="CVE-2014-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0428.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:22.469-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:48.878-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:34.012-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22560 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:15.507-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:21.321-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22560 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:42.924-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:33.779-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141020"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:140766"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:140232"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141122"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:140996"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141224"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141145"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141029"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100224"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100435"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:99593"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100378"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100491"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100434"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100365"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22534" version="55" class="patch">
      <metadata>
        <title>RHSA-2014:0132: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0132-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0132.html"/>
        <reference source="CESA" ref_id="CESA-2014:0132"/>
        <reference source="CVE" ref_id="CVE-2014-1477" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1477.html"/>
        <reference source="CVE" ref_id="CVE-2014-1479" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1479.html"/>
        <reference source="CVE" ref_id="CVE-2014-1481" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1481.html"/>
        <reference source="CVE" ref_id="CVE-2014-1482" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1482.html"/>
        <reference source="CVE" ref_id="CVE-2014-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1486.html"/>
        <reference source="CVE" ref_id="CVE-2014-1487" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1487.html"/>
        <description>The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:16.817-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:47.912-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:31.335-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22534 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:14.930-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:20.704-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22534 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:33.437-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:56.902-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:24.3.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:100310"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="firefox is earlier than 0:24.3.0-2.el6_5" test_ref="oval:org.mitre.oval:tst:100086"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="libvirt-client is earlier than 0:0.10.2-29.el6_5.3" test_ref="oval:org.mitre.oval:tst:113809"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="libvirt-python is earlier than 0:0.10.2-29.el6_5.3" test_ref="oval:org.mitre.oval:tst:113156"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22499" version="25" class="patch">
      <metadata>
        <title>RHSA-2014:0028: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0028-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0028.html"/>
        <reference source="CVE" ref_id="CVE-2014-0491" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0491.html"/>
        <reference source="CVE" ref_id="CVE-2014-0492" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0492.html"/>
        <description>Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR before 4.0.0.1390, Adobe AIR SDK before 4.0.0.1390, and Adobe AIR SDK &amp; Compiler before 4.0.0.1390 allow attackers to defeat the ASLR protection mechanism by leveraging an "address leak."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-28T12:16:52">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-11T14:03:37.224-05:00">DRAFT</status_change>
            <status_change date="2014-03-03T04:01:09.459-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:37.294-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22499 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:31:00.517-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:32:52.671-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:19.918-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22499 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:40.376-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:33.192-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.335-1.el5" test_ref="oval:org.mitre.oval:tst:140999"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.335-1.el6" test_ref="oval:org.mitre.oval:tst:100327"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22479" version="6" class="patch">
      <metadata>
        <title>RHSA-2014:0108: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0108-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0108.html"/>
        <reference source="CESA" ref_id="CESA-2014:0108"/>
        <reference source="CVE" ref_id="CVE-2013-4494" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4494.html"/>
        <description>Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:20.365-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:46.157-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:27.991-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22479 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:18.772-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:19.658-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:100477"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:100345"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:100269"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:99719"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:100460"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:100490"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:100447"/>
          <criterion comment="kernel is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:99541"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:99955"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:100265"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:100320"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:100427"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22431" version="8" class="patch">
      <metadata>
        <title>RHSA-2014:0174: piranha security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>piranha</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0174-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0174.html"/>
        <reference source="CESA" ref_id="CESA-2014:0174"/>
        <reference source="CVE" ref_id="CVE-2013-6492" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6492.html"/>
        <description>The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attackers to bypass authentication and read or modify the LVS configuration via an HTTP POST request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:17.241-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:44.402-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:25.036-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22431 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:17.129-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:19.263-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22431 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:36.044-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:55.367-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="piranha is earlier than 0:0.8.4-26.el5_10.1" test_ref="oval:org.mitre.oval:tst:100501"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22406" version="23" class="patch">
      <metadata>
        <title>RHSA-2014:0163: kvm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0163-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0163.html"/>
        <reference source="CESA" ref_id="CESA-2014:0163"/>
        <reference source="CVE" ref_id="CVE-2013-6367" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6367.html"/>
        <reference source="CVE" ref_id="CVE-2013-6368" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6368.html"/>
        <description>The KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges or cause a denial of service (system crash) via a VAPIC synchronization operation involving a page-end address.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:20.618-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:43.671-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:24.202-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22406 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:18.585-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:17.210-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22406 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:34.049-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:55.074-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="kmod-kvm-debug is earlier than 0:83-266.el5_10.1" test_ref="oval:org.mitre.oval:tst:100519"/>
            <criterion comment="kvm-tools is earlier than 0:83-266.el5_10.1" test_ref="oval:org.mitre.oval:tst:100105"/>
            <criterion comment="kvm-qemu-img is earlier than 0:83-266.el5_10.1" test_ref="oval:org.mitre.oval:tst:100459"/>
            <criterion comment="kvm is earlier than 0:83-266.el5_10.1" test_ref="oval:org.mitre.oval:tst:100594"/>
            <criterion comment="kmod-kvm is earlier than 0:83-266.el5_10.1" test_ref="oval:org.mitre.oval:tst:100575"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="kmod-kvm-debug is earlier than 0:83-266.el5.centos.1" test_ref="oval:org.mitre.oval:tst:114002"/>
            <criterion comment="kvm-tools is earlier than 0:83-266.el5.centos.1" test_ref="oval:org.mitre.oval:tst:113825"/>
            <criterion comment="kvm-qemu-img is earlier than 0:83-266.el5.centos.1" test_ref="oval:org.mitre.oval:tst:113694"/>
            <criterion comment="kvm is earlier than 0:83-266.el5.centos.1" test_ref="oval:org.mitre.oval:tst:113913"/>
            <criterion comment="kmod-kvm is earlier than 0:83-266.el5.centos.1" test_ref="oval:org.mitre.oval:tst:113808"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22390" version="8" class="patch">
      <metadata>
        <title>RHSA-2014:0137: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0137-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0137.html"/>
        <reference source="CVE" ref_id="CVE-2014-0497" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0497.html"/>
        <description>Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:22.127-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:43.472-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:23.825-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22390 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:15.851-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:16.940-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22390 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:42.681-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:32.687-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.336-1.el5" test_ref="oval:org.mitre.oval:tst:141146"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.336-1.el6" test_ref="oval:org.mitre.oval:tst:99514"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22383" version="55" class="patch">
      <metadata>
        <title>RHSA-2010:0534: libpng security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>libpng</product>
          <product>libpng10</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0534-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0534.html"/>
        <reference source="CESA" ref_id="CESA-2010:0534"/>
        <reference source="CVE" ref_id="CVE-2009-2042" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2042.html"/>
        <reference source="CVE" ref_id="CVE-2010-0205" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0205.html"/>
        <reference source="CVE" ref_id="CVE-2010-1205" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1205.html"/>
        <reference source="CVE" ref_id="CVE-2010-2249" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2249.html"/>
        <description>Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:06.637-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:44.243-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:11.332-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libpng is earlier than 2:1.2.10-7.1.el5_5.3" test_ref="oval:org.mitre.oval:tst:99428"/>
          <criterion comment="libpng-devel is earlier than 2:1.2.10-7.1.el5_5.3" test_ref="oval:org.mitre.oval:tst:99642"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22380" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0542: openldap security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openldap</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0542-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0542.html"/>
        <reference source="CESA" ref_id="CESA-2010:0542"/>
        <reference source="CVE" ref_id="CVE-2010-0211" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0211.html"/>
        <reference source="CVE" ref_id="CVE-2010-0212" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0212.html"/>
        <description>OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the Codenomicon LDAPv3 test suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:56.665-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:44.121-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:11.231-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openldap-devel is earlier than 0:2.3.43-12.el5_5.1" test_ref="oval:org.mitre.oval:tst:99614"/>
          <criterion comment="openldap-clients is earlier than 0:2.3.43-12.el5_5.1" test_ref="oval:org.mitre.oval:tst:99598"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.3.43-12.el5_5.1" test_ref="oval:org.mitre.oval:tst:99479"/>
          <criterion comment="compat-openldap is earlier than 0:2.3.43_2.2.29-12.el5_5.1" test_ref="oval:org.mitre.oval:tst:99620"/>
          <criterion comment="openldap is earlier than 0:2.3.43-12.el5_5.1" test_ref="oval:org.mitre.oval:tst:99292"/>
          <criterion comment="openldap-servers is earlier than 0:2.3.43-12.el5_5.1" test_ref="oval:org.mitre.oval:tst:99477"/>
          <criterion comment="openldap-servers-overlays is earlier than 0:2.3.43-12.el5_5.1" test_ref="oval:org.mitre.oval:tst:99626"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22379" version="55" class="patch">
      <metadata>
        <title>RHSA-2010:0737: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0737-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0737.html"/>
        <reference source="CESA" ref_id="CESA-2010:0737"/>
        <reference source="CVE" ref_id="CVE-2010-2806" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2806.html"/>
        <reference source="CVE" ref_id="CVE-2010-2808" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2808.html"/>
        <reference source="CVE" ref_id="CVE-2010-3054" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3054.html"/>
        <reference source="CVE" ref_id="CVE-2010-3311" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3311.html"/>
        <description>Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Compact Font Format (CFF) font file that triggers a heap-based buffer overflow, related to an "input stream position error" issue, a different vulnerability than CVE-2010-1797.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:32.241-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:43.951-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:11.103-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="freetype is earlier than 0:2.2.1-28.el5_5" test_ref="oval:org.mitre.oval:tst:99404"/>
          <criterion comment="freetype-demos is earlier than 0:2.2.1-28.el5_5" test_ref="oval:org.mitre.oval:tst:99397"/>
          <criterion comment="freetype-devel is earlier than 0:2.2.1-28.el5_5" test_ref="oval:org.mitre.oval:tst:98803"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22378" version="68" class="patch">
      <metadata>
        <title>RHSA-2010:0623: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0623-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0623.html"/>
        <reference source="CVE" ref_id="CVE-2010-0209" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0209.html"/>
        <reference source="CVE" ref_id="CVE-2010-2213" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2213.html"/>
        <reference source="CVE" ref_id="CVE-2010-2214" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2214.html"/>
        <reference source="CVE" ref_id="CVE-2010-2215" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2215.html"/>
        <reference source="CVE" ref_id="CVE-2010-2216" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2216.html"/>
        <description>Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2214.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:06.855-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:43.784-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:11.048-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="flash-plugin is earlier than 0:10.1.82.76-1.el5" test_ref="oval:org.mitre.oval:tst:99535"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22375" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0809: xulrunner security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0809-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0809.html"/>
        <reference source="CESA" ref_id="CESA-2010:0809"/>
        <reference source="CVE" ref_id="CVE-2010-3765" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3765.html"/>
        <description>Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:03.358-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:43.679-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:10.991-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="xulrunner is earlier than 0:1.9.2.11-4.el5_5" test_ref="oval:org.mitre.oval:tst:99701"/>
          <criterion comment="xulrunner-devel is earlier than 0:1.9.2.11-4.el5_5" test_ref="oval:org.mitre.oval:tst:98944"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22374" version="133" class="patch">
      <metadata>
        <title>RHSA-2010:0782: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>nss</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0782-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0782.html"/>
        <reference source="CESA" ref_id="CESA-2010:0782"/>
        <reference source="CVE" ref_id="CVE-2010-3170" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3170.html"/>
        <reference source="CVE" ref_id="CVE-2010-3173" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3173.html"/>
        <reference source="CVE" ref_id="CVE-2010-3175" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3175.html"/>
        <reference source="CVE" ref_id="CVE-2010-3176" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3176.html"/>
        <reference source="CVE" ref_id="CVE-2010-3177" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3177.html"/>
        <reference source="CVE" ref_id="CVE-2010-3178" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3178.html"/>
        <reference source="CVE" ref_id="CVE-2010-3179" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3179.html"/>
        <reference source="CVE" ref_id="CVE-2010-3180" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3180.html"/>
        <reference source="CVE" ref_id="CVE-2010-3182" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3182.html"/>
        <reference source="CVE" ref_id="CVE-2010-3183" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3183.html"/>
        <description>The LookupGetterOrSetter function in js3250.dll in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly support window.__lookupGetter__ function calls that lack arguments, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference and application crash) via vectors involving a "dangling pointer" and the JS_ValueToId function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:22.966-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:43.210-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:10.766-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="xulrunner is earlier than 0:1.9.2.11-2.el5" test_ref="oval:org.mitre.oval:tst:99784"/>
          <criterion comment="xulrunner-devel is earlier than 0:1.9.2.11-2.el5" test_ref="oval:org.mitre.oval:tst:99705"/>
          <criterion comment="firefox is earlier than 0:3.6.11-2.el5" test_ref="oval:org.mitre.oval:tst:99096"/>
          <criterion comment="nss is earlier than 0:3.12.8-1.el5" test_ref="oval:org.mitre.oval:tst:99744"/>
          <criterion comment="nss-tools is earlier than 0:3.12.8-1.el5" test_ref="oval:org.mitre.oval:tst:99517"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.8-1.el5" test_ref="oval:org.mitre.oval:tst:99646"/>
          <criterion comment="nss-devel is earlier than 0:3.12.8-1.el5" test_ref="oval:org.mitre.oval:tst:99712"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22369" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0753: kdegraphics security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kdegraphics</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0753-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0753.html"/>
        <reference source="CESA" ref_id="CESA-2010:0753"/>
        <reference source="CVE" ref_id="CVE-2010-3702" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3702.html"/>
        <reference source="CVE" ref_id="CVE-2010-3704" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3704.html"/>
        <description>The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a negative array index, which bypasses input validation and triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:59.639-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:43.109-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:10.658-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kdegraphics is earlier than 7:3.5.4-17.el5_5.1" test_ref="oval:org.mitre.oval:tst:99434"/>
          <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-17.el5_5.1" test_ref="oval:org.mitre.oval:tst:99183"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22364" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0898: kvm security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0898-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0898.html"/>
        <reference source="CESA" ref_id="CESA-2010:0898"/>
        <reference source="CVE" ref_id="CVE-2010-3698" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3698.html"/>
        <description>The KVM implementation in the Linux kernel before 2.6.36 does not properly reload the FS and GS segment registers, which allows host OS users to cause a denial of service (host OS crash) via a KVM_RUN ioctl call in conjunction with a modified Local Descriptor Table (LDT).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:32.178-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:43.009-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:10.470-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kvm-qemu-img is earlier than 0:83-164.el5_5.25" test_ref="oval:org.mitre.oval:tst:99968"/>
          <criterion comment="kvm is earlier than 0:83-164.el5_5.25" test_ref="oval:org.mitre.oval:tst:99776"/>
          <criterion comment="kmod-kvm is earlier than 0:83-164.el5_5.25" test_ref="oval:org.mitre.oval:tst:99986"/>
          <criterion comment="kvm-tools is earlier than 0:83-164.el5_5.25" test_ref="oval:org.mitre.oval:tst:99878"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22361" version="224" class="patch">
      <metadata>
        <title>RHSA-2010:0807: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0807-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0807.html"/>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html"/>
        <reference source="CVE" ref_id="CVE-2010-1321" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1321.html"/>
        <reference source="CVE" ref_id="CVE-2010-3541" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3541.html"/>
        <reference source="CVE" ref_id="CVE-2010-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3548.html"/>
        <reference source="CVE" ref_id="CVE-2010-3549" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3549.html"/>
        <reference source="CVE" ref_id="CVE-2010-3550" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3550.html"/>
        <reference source="CVE" ref_id="CVE-2010-3551" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3551.html"/>
        <reference source="CVE" ref_id="CVE-2010-3556" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3556.html"/>
        <reference source="CVE" ref_id="CVE-2010-3559" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3559.html"/>
        <reference source="CVE" ref_id="CVE-2010-3562" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3562.html"/>
        <reference source="CVE" ref_id="CVE-2010-3565" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3565.html"/>
        <reference source="CVE" ref_id="CVE-2010-3566" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3566.html"/>
        <reference source="CVE" ref_id="CVE-2010-3568" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3568.html"/>
        <reference source="CVE" ref_id="CVE-2010-3569" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3569.html"/>
        <reference source="CVE" ref_id="CVE-2010-3572" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3572.html"/>
        <reference source="CVE" ref_id="CVE-2010-3573" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3573.html"/>
        <reference source="CVE" ref_id="CVE-2010-3574" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3574.html"/>
        <description>Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable downstream vendor that HttpURLConnection does not properly check for the allowHttpTrace permission, which allows untrusted code to perform HTTP TRACE requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:57.617-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:42.524-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:09.965-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99494"/>
          <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99210"/>
          <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99510"/>
          <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99473"/>
          <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99673"/>
          <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99553"/>
          <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99820"/>
          <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99342"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22359" version="55" class="patch">
      <metadata>
        <title>RHSA-2010:0458: perl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>perl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0458-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0458.html"/>
        <reference source="CESA" ref_id="CESA-2010:0458"/>
        <reference source="CVE" ref_id="CVE-2008-5302" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5302.html"/>
        <reference source="CVE" ref_id="CVE-2008-5303" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5303.html"/>
        <reference source="CVE" ref_id="CVE-2010-1168" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1168.html"/>
        <reference source="CVE" ref_id="CVE-2010-1447" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1447.html"/>
        <description>The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2, allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving subroutine references and delayed execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:55.538-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:42.279-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:09.703-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="perl-suidperl is earlier than 4:5.8.8-32.el5_5.1" test_ref="oval:org.mitre.oval:tst:99435"/>
          <criterion comment="perl is earlier than 4:5.8.8-32.el5_5.1" test_ref="oval:org.mitre.oval:tst:99315"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22358" version="224" class="patch">
      <metadata>
        <title>RHSA-2010:0574: java-1.4.2-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.4.2-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0574-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0574.html"/>
        <reference source="CVE" ref_id="CVE-2010-0084" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0084.html"/>
        <reference source="CVE" ref_id="CVE-2010-0085" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0085.html"/>
        <reference source="CVE" ref_id="CVE-2010-0087" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0087.html"/>
        <reference source="CVE" ref_id="CVE-2010-0088" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0088.html"/>
        <reference source="CVE" ref_id="CVE-2010-0089" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0089.html"/>
        <reference source="CVE" ref_id="CVE-2010-0091" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0091.html"/>
        <reference source="CVE" ref_id="CVE-2010-0095" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0095.html"/>
        <reference source="CVE" ref_id="CVE-2010-0839" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0839.html"/>
        <reference source="CVE" ref_id="CVE-2010-0840" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0840.html"/>
        <reference source="CVE" ref_id="CVE-2010-0841" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0841.html"/>
        <reference source="CVE" ref_id="CVE-2010-0842" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0842.html"/>
        <reference source="CVE" ref_id="CVE-2010-0843" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0843.html"/>
        <reference source="CVE" ref_id="CVE-2010-0844" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0844.html"/>
        <reference source="CVE" ref_id="CVE-2010-0846" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0846.html"/>
        <reference source="CVE" ref_id="CVE-2010-0847" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0847.html"/>
        <reference source="CVE" ref_id="CVE-2010-0848" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0848.html"/>
        <reference source="CVE" ref_id="CVE-2010-0849" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0849.html"/>
        <description>Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow in a decoding routine used by the JPEGImageDecoderImpl interface, which allows code execution via a crafted JPEG image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:16.264-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:41.737-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:09.276-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99530"/>
          <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99573"/>
          <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99490"/>
          <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99590"/>
          <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99321"/>
          <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99616"/>
          <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99457"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22356" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0812: thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0812-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0812.html"/>
        <reference source="CESA" ref_id="CESA-2010:0812"/>
        <reference source="CVE" ref_id="CVE-2010-3765" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3765.html"/>
        <description>Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:34.803-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:41.651-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:09.179-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-10.el5_5" test_ref="oval:org.mitre.oval:tst:99791"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22355" version="159" class="patch">
      <metadata>
        <title>RHSA-2010:0681: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>nspr</product>
          <product>nss</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0681-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0681.html"/>
        <reference source="CESA" ref_id="CESA-2010:0681"/>
        <reference source="CVE" ref_id="CVE-2010-2760" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2760.html"/>
        <reference source="CVE" ref_id="CVE-2010-2762" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2762.html"/>
        <reference source="CVE" ref_id="CVE-2010-2764" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2764.html"/>
        <reference source="CVE" ref_id="CVE-2010-2765" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2765.html"/>
        <reference source="CVE" ref_id="CVE-2010-2766" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2766.html"/>
        <reference source="CVE" ref_id="CVE-2010-2767" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2767.html"/>
        <reference source="CVE" ref_id="CVE-2010-2768" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2768.html"/>
        <reference source="CVE" ref_id="CVE-2010-2769" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2769.html"/>
        <reference source="CVE" ref_id="CVE-2010-3166" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3166.html"/>
        <reference source="CVE" ref_id="CVE-2010-3167" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3167.html"/>
        <reference source="CVE" ref_id="CVE-2010-3168" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3168.html"/>
        <reference source="CVE" ref_id="CVE-2010-3169" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3169.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:02.442-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:41.304-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:08.759-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="xulrunner is earlier than 0:1.9.2.9-1.el5" test_ref="oval:org.mitre.oval:tst:99623"/>
          <criterion comment="xulrunner-devel is earlier than 0:1.9.2.9-1.el5" test_ref="oval:org.mitre.oval:tst:99649"/>
          <criterion comment="firefox is earlier than 0:3.6.9-2.el5" test_ref="oval:org.mitre.oval:tst:99633"/>
          <criterion comment="nspr-devel is earlier than 0:4.8.6-1.el5" test_ref="oval:org.mitre.oval:tst:99666"/>
          <criterion comment="nspr is earlier than 0:4.8.6-1.el5" test_ref="oval:org.mitre.oval:tst:98911"/>
          <criterion comment="nss is earlier than 0:3.12.7-2.el5" test_ref="oval:org.mitre.oval:tst:99550"/>
          <criterion comment="nss-tools is earlier than 0:3.12.7-2.el5" test_ref="oval:org.mitre.oval:tst:99345"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.7-2.el5" test_ref="oval:org.mitre.oval:tst:99498"/>
          <criterion comment="nss-devel is earlier than 0:3.12.7-2.el5" test_ref="oval:org.mitre.oval:tst:99669"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22354" version="81" class="patch">
      <metadata>
        <title>RHSA-2010:0636: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0636-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0636.html"/>
        <reference source="CVE" ref_id="CVE-2010-0209" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0209.html"/>
        <reference source="CVE" ref_id="CVE-2010-2213" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2213.html"/>
        <reference source="CVE" ref_id="CVE-2010-2214" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2214.html"/>
        <reference source="CVE" ref_id="CVE-2010-2215" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2215.html"/>
        <reference source="CVE" ref_id="CVE-2010-2216" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2216.html"/>
        <reference source="CVE" ref_id="CVE-2010-2862" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2862.html"/>
        <description>Integer overflow in CoolType.dll in Adobe Reader 8.2.3 and 9.3.3, and Acrobat 9.3.3, allows remote attackers to execute arbitrary code via a TrueType font with a large maxCompositePoints value in a Maximum Profile (maxp) table.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:12.250-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:41.153-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:08.531-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="acroread-plugin is earlier than 0:9.3.4-1.el5" test_ref="oval:org.mitre.oval:tst:99093"/>
          <criterion comment="acroread is earlier than 0:9.3.4-1.el5" test_ref="oval:org.mitre.oval:tst:99697"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22353" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0556: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0556-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0556.html"/>
        <reference source="CESA" ref_id="CESA-2010:0556"/>
        <reference source="CVE" ref_id="CVE-2010-2755" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2755.html"/>
        <description>layout/generic/nsObjectFrame.cpp in Mozilla Firefox 3.6.7 does not properly free memory in the parameter array of a plugin instance, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted HTML document, related to the DATA and SRC attributes of an OBJECT element. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-1214.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:45.350-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:41.034-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:08.412-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="xulrunner is earlier than 0:1.9.2.7-3.el5" test_ref="oval:org.mitre.oval:tst:99667"/>
          <criterion comment="xulrunner-devel is earlier than 0:1.9.2.7-3.el5" test_ref="oval:org.mitre.oval:tst:99443"/>
          <criterion comment="firefox is earlier than 0:3.6.7-3.el5" test_ref="oval:org.mitre.oval:tst:99558"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22351" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0950: apr-util security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>apr-util</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0950-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0950.html"/>
        <reference source="CVE" ref_id="CVE-2010-1623" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1623.html"/>
        <description>Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:00.765-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:40.921-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:08.291-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="apr-util-mysql is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:99823"/>
            <criterion comment="apr-util-devel is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:99298"/>
            <criterion comment="apr-util-docs is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:99866"/>
            <criterion comment="apr-util is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:100054"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="apr-util-mysql is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99848"/>
            <criterion comment="apr-util-odbc is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:100112"/>
            <criterion comment="apr-util-devel is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:100092"/>
            <criterion comment="apr-util-ldap is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99963"/>
            <criterion comment="apr-util is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99933"/>
            <criterion comment="apr-util-pgsql is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99237"/>
            <criterion comment="apr-util-sqlite is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:100104"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22345" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0528: avahi security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>avahi</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0528-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0528.html"/>
        <reference source="CESA" ref_id="CESA-2010:0528"/>
        <reference source="CVE" ref_id="CVE-2009-0758" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0758.html"/>
        <reference source="CVE" ref_id="CVE-2010-2244" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2244.html"/>
        <description>The AvahiDnsPacket function in avahi-core/socket.c in avahi-daemon in Avahi 0.6.16 and 0.6.25 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNS packet with an invalid checksum followed by a DNS packet with a valid checksum, a different vulnerability than CVE-2008-5081.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:17.753-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:40.795-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:08.137-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="avahi-compat-howl is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:99341"/>
          <criterion comment="avahi-glib-devel is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:99639"/>
          <criterion comment="avahi is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:99533"/>
          <criterion comment="avahi-compat-howl-devel is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:99658"/>
          <criterion comment="avahi-compat-libdns_sd is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:99566"/>
          <criterion comment="avahi-glib is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:99578"/>
          <criterion comment="avahi-tools is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:99671"/>
          <criterion comment="avahi-qt3-devel is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:99072"/>
          <criterion comment="avahi-compat-libdns_sd-devel is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:99654"/>
          <criterion comment="avahi-qt3 is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:99179"/>
          <criterion comment="avahi-devel is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:99142"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22344" version="211" class="patch">
      <metadata>
        <title>RHSA-2010:0547: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0547-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0547.html"/>
        <reference source="CESA" ref_id="CESA-2010:0547"/>
        <reference source="CVE" ref_id="CVE-2010-0654" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0654.html"/>
        <reference source="CVE" ref_id="CVE-2010-1205" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1205.html"/>
        <reference source="CVE" ref_id="CVE-2010-1206" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1206.html"/>
        <reference source="CVE" ref_id="CVE-2010-1207" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1207.html"/>
        <reference source="CVE" ref_id="CVE-2010-1208" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1208.html"/>
        <reference source="CVE" ref_id="CVE-2010-1209" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1209.html"/>
        <reference source="CVE" ref_id="CVE-2010-1210" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1210.html"/>
        <reference source="CVE" ref_id="CVE-2010-1211" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1211.html"/>
        <reference source="CVE" ref_id="CVE-2010-1212" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1212.html"/>
        <reference source="CVE" ref_id="CVE-2010-1213" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1213.html"/>
        <reference source="CVE" ref_id="CVE-2010-1214" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1214.html"/>
        <reference source="CVE" ref_id="CVE-2010-1215" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1215.html"/>
        <reference source="CVE" ref_id="CVE-2010-2751" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2751.html"/>
        <reference source="CVE" ref_id="CVE-2010-2752" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2752.html"/>
        <reference source="CVE" ref_id="CVE-2010-2753" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2753.html"/>
        <reference source="CVE" ref_id="CVE-2010-2754" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2754.html"/>
        <description>dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not properly suppress a script's URL in certain circumstances involving a redirect and an error message, which allows remote attackers to obtain sensitive information about script parameters via a crafted HTML document, related to the window.onerror handler.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:57.014-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:40.329-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:07.575-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="xulrunner is earlier than 0:1.9.2.7-2.el5" test_ref="oval:org.mitre.oval:tst:99527"/>
          <criterion comment="xulrunner-devel is earlier than 0:1.9.2.7-2.el5" test_ref="oval:org.mitre.oval:tst:99114"/>
          <criterion comment="firefox is earlier than 0:3.6.7-2.el5" test_ref="oval:org.mitre.oval:tst:99447"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22337" version="146" class="patch">
      <metadata>
        <title>RHSA-2010:0825: mysql security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0825-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0825.html"/>
        <reference source="CESA" ref_id="CESA-2010:0825"/>
        <reference source="CVE" ref_id="CVE-2010-3677" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3677.html"/>
        <reference source="CVE" ref_id="CVE-2010-3680" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3680.html"/>
        <reference source="CVE" ref_id="CVE-2010-3681" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3681.html"/>
        <reference source="CVE" ref_id="CVE-2010-3682" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3682.html"/>
        <reference source="CVE" ref_id="CVE-2010-3833" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3833.html"/>
        <reference source="CVE" ref_id="CVE-2010-3835" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3835.html"/>
        <reference source="CVE" ref_id="CVE-2010-3836" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3836.html"/>
        <reference source="CVE" ref_id="CVE-2010-3837" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3837.html"/>
        <reference source="CVE" ref_id="CVE-2010-3838" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3838.html"/>
        <reference source="CVE" ref_id="CVE-2010-3839" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3839.html"/>
        <reference source="CVE" ref_id="CVE-2010-3840" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3840.html"/>
        <description>The Gis_line_string::init_from_wkb function in sql/spatial.cc in MySQL 5.1 before 5.1.51 allows remote authenticated users to cause a denial of service (server crash) by calling the PolyFromWKB function with Well-Known Binary (WKB) data containing a crafted number of (1) line strings or (2) line points.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:06.458-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:39.808-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:06.731-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mysql-test is earlier than 0:5.0.77-4.el5_5.4" test_ref="oval:org.mitre.oval:tst:99805"/>
          <criterion comment="mysql is earlier than 0:5.0.77-4.el5_5.4" test_ref="oval:org.mitre.oval:tst:99302"/>
          <criterion comment="mysql-server is earlier than 0:5.0.77-4.el5_5.4" test_ref="oval:org.mitre.oval:tst:98870"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.77-4.el5_5.4" test_ref="oval:org.mitre.oval:tst:99303"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.77-4.el5_5.4" test_ref="oval:org.mitre.oval:tst:99715"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22336" version="250" class="patch">
      <metadata>
        <title>RHSA-2010:0743: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0743-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0743.html"/>
        <reference source="CVE" ref_id="CVE-2010-2883" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2883.html"/>
        <reference source="CVE" ref_id="CVE-2010-2884" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2884.html"/>
        <reference source="CVE" ref_id="CVE-2010-2887" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2887.html"/>
        <reference source="CVE" ref_id="CVE-2010-2889" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2889.html"/>
        <reference source="CVE" ref_id="CVE-2010-2890" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2890.html"/>
        <reference source="CVE" ref_id="CVE-2010-3619" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3619.html"/>
        <reference source="CVE" ref_id="CVE-2010-3620" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3620.html"/>
        <reference source="CVE" ref_id="CVE-2010-3621" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3621.html"/>
        <reference source="CVE" ref_id="CVE-2010-3622" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3622.html"/>
        <reference source="CVE" ref_id="CVE-2010-3625" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3625.html"/>
        <reference source="CVE" ref_id="CVE-2010-3626" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3626.html"/>
        <reference source="CVE" ref_id="CVE-2010-3627" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3627.html"/>
        <reference source="CVE" ref_id="CVE-2010-3628" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3628.html"/>
        <reference source="CVE" ref_id="CVE-2010-3629" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3629.html"/>
        <reference source="CVE" ref_id="CVE-2010-3630" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3630.html"/>
        <reference source="CVE" ref_id="CVE-2010-3632" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3632.html"/>
        <reference source="CVE" ref_id="CVE-2010-3656" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3656.html"/>
        <reference source="CVE" ref_id="CVE-2010-3657" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3657.html"/>
        <reference source="CVE" ref_id="CVE-2010-3658" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3658.html"/>
        <description>Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2890, CVE-2010-3619, CVE-2010-3621, CVE-2010-3622, CVE-2010-3628, and CVE-2010-3632.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:32.471-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:39.335-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:06.080-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="acroread-plugin is earlier than 0:9.4.0-1.el5" test_ref="oval:org.mitre.oval:tst:99506"/>
          <criterion comment="acroread is earlier than 0:9.4.0-1.el5" test_ref="oval:org.mitre.oval:tst:99648"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22332" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0505: perl-Archive-Tar security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>perl-Archive-Tar</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0505-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0505.html"/>
        <reference source="CESA" ref_id="CESA-2010:0505"/>
        <reference source="CVE" ref_id="CVE-2007-4829" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4829.html"/>
        <description>Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path or has ".." sequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:23.678-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:39.251-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:05.957-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="perl-Archive-Tar is earlier than 1:1.39.1-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99636"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22325" version="198" class="patch">
      <metadata>
        <title>RHSA-2010:0829: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0829-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0829.html"/>
        <reference source="CVE" ref_id="CVE-2010-3636" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3636.html"/>
        <reference source="CVE" ref_id="CVE-2010-3639" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3639.html"/>
        <reference source="CVE" ref_id="CVE-2010-3640" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3640.html"/>
        <reference source="CVE" ref_id="CVE-2010-3641" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3641.html"/>
        <reference source="CVE" ref_id="CVE-2010-3642" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3642.html"/>
        <reference source="CVE" ref_id="CVE-2010-3643" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3643.html"/>
        <reference source="CVE" ref_id="CVE-2010-3644" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3644.html"/>
        <reference source="CVE" ref_id="CVE-2010-3645" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3645.html"/>
        <reference source="CVE" ref_id="CVE-2010-3646" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3646.html"/>
        <reference source="CVE" ref_id="CVE-2010-3647" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3647.html"/>
        <reference source="CVE" ref_id="CVE-2010-3648" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3648.html"/>
        <reference source="CVE" ref_id="CVE-2010-3649" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3649.html"/>
        <reference source="CVE" ref_id="CVE-2010-3650" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3650.html"/>
        <reference source="CVE" ref_id="CVE-2010-3652" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3652.html"/>
        <reference source="CVE" ref_id="CVE-2010-3654" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3654.html"/>
        <description>Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted SWF content, as exploited in the wild in October 2010.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:55.783-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:38.754-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:05.261-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="flash-plugin is earlier than 0:10.1.102.64-1.el5" test_ref="oval:org.mitre.oval:tst:99824"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22324" version="42" class="patch">
      <metadata>
        <title>RHSA-2010:0780: thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0780-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0780.html"/>
        <reference source="CESA" ref_id="CESA-2010:0780"/>
        <reference source="CVE" ref_id="CVE-2010-3176" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3176.html"/>
        <reference source="CVE" ref_id="CVE-2010-3180" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3180.html"/>
        <reference source="CVE" ref_id="CVE-2010-3182" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3182.html"/>
        <description>A certain application-launch script in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Linux places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:37.202-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:38.630-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:05.191-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-9.el5" test_ref="oval:org.mitre.oval:tst:99534"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22313" version="302" class="patch">
      <metadata>
        <title>RHSA-2010:0987: java-1.6.0-ibm security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0987-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0987.html"/>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html"/>
        <reference source="CVE" ref_id="CVE-2010-1321" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1321.html"/>
        <reference source="CVE" ref_id="CVE-2010-3541" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3541.html"/>
        <reference source="CVE" ref_id="CVE-2010-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3548.html"/>
        <reference source="CVE" ref_id="CVE-2010-3549" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3549.html"/>
        <reference source="CVE" ref_id="CVE-2010-3550" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3550.html"/>
        <reference source="CVE" ref_id="CVE-2010-3551" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3551.html"/>
        <reference source="CVE" ref_id="CVE-2010-3553" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3553.html"/>
        <reference source="CVE" ref_id="CVE-2010-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3555.html"/>
        <reference source="CVE" ref_id="CVE-2010-3556" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3556.html"/>
        <reference source="CVE" ref_id="CVE-2010-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3557.html"/>
        <reference source="CVE" ref_id="CVE-2010-3558" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3558.html"/>
        <reference source="CVE" ref_id="CVE-2010-3560" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3560.html"/>
        <reference source="CVE" ref_id="CVE-2010-3562" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3562.html"/>
        <reference source="CVE" ref_id="CVE-2010-3563" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3563.html"/>
        <reference source="CVE" ref_id="CVE-2010-3565" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3565.html"/>
        <reference source="CVE" ref_id="CVE-2010-3566" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3566.html"/>
        <reference source="CVE" ref_id="CVE-2010-3568" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3568.html"/>
        <reference source="CVE" ref_id="CVE-2010-3569" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3569.html"/>
        <reference source="CVE" ref_id="CVE-2010-3571" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3571.html"/>
        <reference source="CVE" ref_id="CVE-2010-3572" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3572.html"/>
        <reference source="CVE" ref_id="CVE-2010-3573" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3573.html"/>
        <reference source="CVE" ref_id="CVE-2010-3574" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3574.html"/>
        <description>Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable downstream vendor that HttpURLConnection does not properly check for the allowHttpTrace permission, which allows untrusted code to perform HTTP TRACE requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:38.612-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:37.857-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:04.398-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:100028"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:99711"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:99988"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:99645"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:99841"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:100039"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:100029"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:100048"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:99840"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:100131"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:99487"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:99638"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:99977"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:99913"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:99549"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22305" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0749: poppler security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>poppler</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0749-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0749.html"/>
        <reference source="CESA" ref_id="CESA-2010:0749"/>
        <reference source="CVE" ref_id="CVE-2010-3702" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3702.html"/>
        <reference source="CVE" ref_id="CVE-2010-3704" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3704.html"/>
        <description>The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a negative array index, which bypasses input validation and triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:30.997-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:37.749-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:04.180-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_5.14" test_ref="oval:org.mitre.oval:tst:98991"/>
          <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_5.14" test_ref="oval:org.mitre.oval:tst:99539"/>
          <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_5.14" test_ref="oval:org.mitre.oval:tst:99691"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22302" version="42" class="patch">
      <metadata>
        <title>RHSA-2010:0490: cups security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0490-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0490.html"/>
        <reference source="CESA" ref_id="CESA-2010:0490"/>
        <reference source="CVE" ref_id="CVE-2010-0540" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0540.html"/>
        <reference source="CVE" ref_id="CVE-2010-0542" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0542.html"/>
        <reference source="CVE" ref_id="CVE-2010-1748" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1748.html"/>
        <description>The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&amp;URL=% and (2) /admin?URL=/admin/&amp;OP=% URIs.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:37.533-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:37.611-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:04.015-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="cups-lpd is earlier than 1:1.3.7-18.el5_5.4" test_ref="oval:org.mitre.oval:tst:99332"/>
          <criterion comment="cups-devel is earlier than 1:1.3.7-18.el5_5.4" test_ref="oval:org.mitre.oval:tst:99115"/>
          <criterion comment="cups-libs is earlier than 1:1.3.7-18.el5_5.4" test_ref="oval:org.mitre.oval:tst:98630"/>
          <criterion comment="cups is earlier than 1:1.3.7-18.el5_5.4" test_ref="oval:org.mitre.oval:tst:99491"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22300" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0704: kernel security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0704-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0704.html"/>
        <reference source="CESA" ref_id="CESA-2010:0704"/>
        <reference source="CVE" ref_id="CVE-2010-3081" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3081.html"/>
        <description>The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer, which allows local users to gain privileges by leveraging the ability of the compat_mc_getsockopt function (aka the MCAST_MSFILTER getsockopt support) to control a certain length value, related to a "stack pointer underflow" issue, as exploited in the wild in September 2010.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:20.586-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:37.498-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:03.898-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:99617"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:99730"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:99732"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:99745"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:99563"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:99670"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:99634"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:98800"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:99297"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:99450"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:99060"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:99390"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22297" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0603: gnupg2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gnupg2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0603-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0603.html"/>
        <reference source="CESA" ref_id="CESA-2010:0603"/>
        <reference source="CVE" ref_id="CVE-2010-2547" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2547.html"/>
        <description>Use-after-free vulnerability in kbx/keybox-blob.c in GPGSM in GnuPG 2.x through 2.0.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a certificate with a large number of Subject Alternate Names, which is not properly handled in a realloc operation when importing the certificate or verifying its signature.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:31.278-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:37.421-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:03.806-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="gnupg2 is earlier than 0:2.0.10-3.el5_5.1" test_ref="oval:org.mitre.oval:tst:99194"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22296" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0785: quagga security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>quagga</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0785-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0785.html"/>
        <reference source="CESA" ref_id="CESA-2010:0785"/>
        <reference source="CVE" ref_id="CVE-2007-4826" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4826.html"/>
        <reference source="CVE" ref_id="CVE-2010-2948" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2948.html"/>
        <description>Stack-based buffer overflow in the bgp_route_refresh_receive function in bgp_packet.c in bgpd in Quagga before 0.99.17 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a malformed Outbound Route Filtering (ORF) record in a BGP ROUTE-REFRESH (RR) message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:02.269-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:37.316-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:03.692-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="quagga-devel is earlier than 0:0.98.6-5.el5_5.2" test_ref="oval:org.mitre.oval:tst:99735"/>
          <criterion comment="quagga-contrib is earlier than 0:0.98.6-5.el5_5.2" test_ref="oval:org.mitre.oval:tst:99470"/>
          <criterion comment="quagga is earlier than 0:0.98.6-5.el5_5.2" test_ref="oval:org.mitre.oval:tst:99525"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22294" version="42" class="patch">
      <metadata>
        <title>RHSA-2010:0976: bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0976-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0976.html"/>
        <reference source="CESA" ref_id="CESA-2010:0976"/>
        <reference source="CVE" ref_id="CVE-2010-3613" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3613.html"/>
        <reference source="CVE" ref_id="CVE-2010-3614" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3614.html"/>
        <reference source="CVE" ref_id="CVE-2010-3762" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3762.html"/>
        <description>ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly handle certain bad signatures if multiple trust anchors exist for a single zone, which allows remote attackers to cause a denial of service (daemon crash) via a DNS query.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:16.962-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:37.058-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:03.423-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="bind-chroot is earlier than 30:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:99481"/>
          <criterion comment="bind-devel is earlier than 30:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:100129"/>
          <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:99674"/>
          <criterion comment="bind-utils is earlier than 30:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:99827"/>
          <criterion comment="bind-sdb is earlier than 30:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:100050"/>
          <criterion comment="bind is earlier than 30:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:99433"/>
          <criterion comment="bind-libs is earlier than 30:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:99440"/>
          <criterion comment="caching-nameserver is earlier than 30:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:99604"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22292" version="207" class="patch">
      <metadata>
        <title>RHSA-2014:0134: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0134-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0134.html"/>
        <reference source="CVE" ref_id="CVE-2013-5878" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5878.html"/>
        <reference source="CVE" ref_id="CVE-2013-5884" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5884.html"/>
        <reference source="CVE" ref_id="CVE-2013-5887" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5887.html"/>
        <reference source="CVE" ref_id="CVE-2013-5888" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5888.html"/>
        <reference source="CVE" ref_id="CVE-2013-5889" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5889.html"/>
        <reference source="CVE" ref_id="CVE-2013-5896" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5896.html"/>
        <reference source="CVE" ref_id="CVE-2013-5898" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5898.html"/>
        <reference source="CVE" ref_id="CVE-2013-5899" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5899.html"/>
        <reference source="CVE" ref_id="CVE-2013-5907" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5907.html"/>
        <reference source="CVE" ref_id="CVE-2013-5910" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5910.html"/>
        <reference source="CVE" ref_id="CVE-2014-0368" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0368.html"/>
        <reference source="CVE" ref_id="CVE-2014-0373" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0373.html"/>
        <reference source="CVE" ref_id="CVE-2014-0375" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0375.html"/>
        <reference source="CVE" ref_id="CVE-2014-0376" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0376.html"/>
        <reference source="CVE" ref_id="CVE-2014-0387" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0387.html"/>
        <reference source="CVE" ref_id="CVE-2014-0403" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0403.html"/>
        <reference source="CVE" ref_id="CVE-2014-0410" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0410.html"/>
        <reference source="CVE" ref_id="CVE-2014-0411" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0411.html"/>
        <reference source="CVE" ref_id="CVE-2014-0415" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0415.html"/>
        <reference source="CVE" ref_id="CVE-2014-0416" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0416.html"/>
        <reference source="CVE" ref_id="CVE-2014-0417" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0417.html"/>
        <reference source="CVE" ref_id="CVE-2014-0422" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0422.html"/>
        <reference source="CVE" ref_id="CVE-2014-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0423.html"/>
        <reference source="CVE" ref_id="CVE-2014-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0424.html"/>
        <reference source="CVE" ref_id="CVE-2014-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0428.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:18.764-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:41.561-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:20.929-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22292 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:16.349-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:15.660-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22292 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:42.353-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:31.690-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:140896"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:140881"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141052"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141081"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141036"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141057"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100082"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100483"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:99949"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100370"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100425"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100295"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22291" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0632: qspice-client security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>qspice-client</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0632-03" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0632.html"/>
        <reference source="CESA" ref_id="CESA-2010:0632"/>
        <reference source="CVE" ref_id="CVE-2010-2792" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2792.html"/>
        <description>Race condition in the SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to obtain sensitive information, and conduct man-in-the-middle attacks, by providing a UNIX socket for communication between this plug-in and the client (aka qspice-client) in qspice 0.3.0, and then accessing this socket.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:04.640-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:36.955-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:03.336-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="qspice-client is earlier than 0:0.3.0-4.el5_5" test_ref="oval:org.mitre.oval:tst:98806"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22284" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0935: java-1.4.2-ibm security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.4.2-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0935-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0935.html"/>
        <reference source="CVE" ref_id="CVE-2010-1321" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1321.html"/>
        <reference source="CVE" ref_id="CVE-2010-3574" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3574.html"/>
        <description>Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable downstream vendor that HttpURLConnection does not properly check for the allowHttpTrace permission, which allows untrusted code to perform HTTP TRACE requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:18.759-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:36.143-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:02.614-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.7-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:99458"/>
          <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.7-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:100088"/>
          <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.7-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:99714"/>
          <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.7-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:99812"/>
          <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.7-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:99997"/>
          <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.7-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:100097"/>
          <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.7-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:99789"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22278" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0889: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0889-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0889.html"/>
        <reference source="CESA" ref_id="CESA-2010:0889"/>
        <reference source="CVE" ref_id="CVE-2010-3855" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3855.html"/>
        <description>Buffer overflow in the ft_var_readpackedpoints function in truetype/ttgxvar.c in FreeType 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TrueType GX font.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:27.810-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:36.039-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:02.492-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-28.el5_5.1" test_ref="oval:org.mitre.oval:tst:99759"/>
            <criterion comment="freetype is earlier than 0:2.2.1-28.el5_5.1" test_ref="oval:org.mitre.oval:tst:99767"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-28.el5_5.1" test_ref="oval:org.mitre.oval:tst:100020"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_0.2" test_ref="oval:org.mitre.oval:tst:99899"/>
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_0.2" test_ref="oval:org.mitre.oval:tst:99736"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_0.2" test_ref="oval:org.mitre.oval:tst:99941"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22277" version="94" class="patch">
      <metadata>
        <title>RHSA-2010:0723: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0723-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0723.html"/>
        <reference source="CESA" ref_id="CESA-2010:0723"/>
        <reference source="CVE" ref_id="CVE-2010-1083" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1083.html"/>
        <reference source="CVE" ref_id="CVE-2010-2492" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2492.html"/>
        <reference source="CVE" ref_id="CVE-2010-2798" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2798.html"/>
        <reference source="CVE" ref_id="CVE-2010-2938" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2938.html"/>
        <reference source="CVE" ref_id="CVE-2010-2942" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2942.html"/>
        <reference source="CVE" ref_id="CVE-2010-2943" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2943.html"/>
        <reference source="CVE" ref_id="CVE-2010-3015" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3015.html"/>
        <description>Integer overflow in the ext4_ext_get_blocks function in fs/ext4/extents.c in the Linux kernel before 2.6.34 allows local users to cause a denial of service (BUG and system crash) via a write operation on the last block of a large file, followed by a sync operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:48.471-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:35.719-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:02.144-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:98897"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:99472"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:99751"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:98871"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:99515"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:99722"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:99765"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:99695"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:98776"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:99703"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:99425"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:99126"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22271" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0788: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0788-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0788.html"/>
        <reference source="CESA" ref_id="CESA-2010:0788"/>
        <reference source="CVE" ref_id="CVE-2010-1624" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1624.html"/>
        <reference source="CVE" ref_id="CVE-2010-3711" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3711.html"/>
        <description>libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:29.763-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:35.173-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:01.524-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libpurple-perl is earlier than 0:2.6.6-5.el5_5" test_ref="oval:org.mitre.oval:tst:99809"/>
          <criterion comment="finch is earlier than 0:2.6.6-5.el5_5" test_ref="oval:org.mitre.oval:tst:99782"/>
          <criterion comment="libpurple is earlier than 0:2.6.6-5.el5_5" test_ref="oval:org.mitre.oval:tst:99521"/>
          <criterion comment="pidgin is earlier than 0:2.6.6-5.el5_5" test_ref="oval:org.mitre.oval:tst:99787"/>
          <criterion comment="pidgin-perl is earlier than 0:2.6.6-5.el5_5" test_ref="oval:org.mitre.oval:tst:99778"/>
          <criterion comment="libpurple-devel is earlier than 0:2.6.6-5.el5_5" test_ref="oval:org.mitre.oval:tst:99504"/>
          <criterion comment="pidgin-devel is earlier than 0:2.6.6-5.el5_5" test_ref="oval:org.mitre.oval:tst:99661"/>
          <criterion comment="finch-devel is earlier than 0:2.6.6-5.el5_5" test_ref="oval:org.mitre.oval:tst:99503"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.6.6-5.el5_5" test_ref="oval:org.mitre.oval:tst:98903"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22268" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0934: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0934-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0934.html"/>
        <reference source="CVE" ref_id="CVE-2010-3654" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3654.html"/>
        <reference source="CVE" ref_id="CVE-2010-4091" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4091.html"/>
        <description>The EScript.api plugin in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.1, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document that triggers memory corruption, involving the printSeps function. NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:25.581-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:34.977-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:01.277-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.4.1-1.el5" test_ref="oval:org.mitre.oval:tst:99895"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.1-1.el5" test_ref="oval:org.mitre.oval:tst:99982"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.4.1-1.el6" test_ref="oval:org.mitre.oval:tst:99687"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.1-1.el6" test_ref="oval:org.mitre.oval:tst:100085"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22267" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0549: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0549-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0549.html"/>
        <reference source="CVE" ref_id="CVE-2010-0887" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0887.html"/>
        <description>Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business JDK and JRE 6 Update 18 and 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:17.192-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:34.877-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:01.172-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.8.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:99635"/>
          <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.8.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:99260"/>
          <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.8.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:99313"/>
          <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.8.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:99316"/>
          <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.8.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:99664"/>
          <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.8.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:99520"/>
          <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.8.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:99544"/>
          <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.8.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:99595"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22253" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0533: pcsc-lite security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>pcsc-lite</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0533-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0533.html"/>
        <reference source="CESA" ref_id="CESA-2010:0533"/>
        <reference source="CVE" ref_id="CVE-2009-4901" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4901.html"/>
        <reference source="CVE" ref_id="CVE-2010-0407" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0407.html"/>
        <description>Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 allow local users to gain privileges via crafted message data, which is improperly demarshalled.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:44.954-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:34.746-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:00.958-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="pcsc-lite-libs is earlier than 0:1.4.4-4.el5_5" test_ref="oval:org.mitre.oval:tst:99319"/>
          <criterion comment="pcsc-lite-doc is earlier than 0:1.4.4-4.el5_5" test_ref="oval:org.mitre.oval:tst:99643"/>
          <criterion comment="pcsc-lite is earlier than 0:1.4.4-4.el5_5" test_ref="oval:org.mitre.oval:tst:99618"/>
          <criterion comment="pcsc-lite-devel is earlier than 0:1.4.4-4.el5_5" test_ref="oval:org.mitre.oval:tst:99387"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22251" version="224" class="patch">
      <metadata>
        <title>RHSA-2010:0400: tetex security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>tetex</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0400-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0400.html"/>
        <reference source="CESA" ref_id="CESA-2010:0400"/>
        <reference source="CVE" ref_id="CVE-2009-0146" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0146.html"/>
        <reference source="CVE" ref_id="CVE-2009-0147" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0147.html"/>
        <reference source="CVE" ref_id="CVE-2009-0166" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0166.html"/>
        <reference source="CVE" ref_id="CVE-2009-0195" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0195.html"/>
        <reference source="CVE" ref_id="CVE-2009-0791" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0791.html"/>
        <reference source="CVE" ref_id="CVE-2009-0799" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0799.html"/>
        <reference source="CVE" ref_id="CVE-2009-0800" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0800.html"/>
        <reference source="CVE" ref_id="CVE-2009-1179" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1179.html"/>
        <reference source="CVE" ref_id="CVE-2009-1180" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1180.html"/>
        <reference source="CVE" ref_id="CVE-2009-1181" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1181.html"/>
        <reference source="CVE" ref_id="CVE-2009-1182" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1182.html"/>
        <reference source="CVE" ref_id="CVE-2009-1183" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1183.html"/>
        <reference source="CVE" ref_id="CVE-2009-3608" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3608.html"/>
        <reference source="CVE" ref_id="CVE-2009-3609" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3609.html"/>
        <reference source="CVE" ref_id="CVE-2010-0739" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0739.html"/>
        <reference source="CVE" ref_id="CVE-2010-0829" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0829.html"/>
        <reference source="CVE" ref_id="CVE-2010-1440" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1440.html"/>
        <description>Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a special command in a DVI file, related to the (1) predospecial and (2) bbdospecial functions, a different vulnerability than CVE-2010-0739.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:02.715-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:34.214-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:00.449-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:99421"/>
          <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:99270"/>
          <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:99392"/>
          <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:99367"/>
          <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:99284"/>
          <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:98819"/>
          <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:98820"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22250" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0926: krb5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0926-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0926.html"/>
        <reference source="CESA" ref_id="CESA-2010:0926"/>
        <reference source="CVE" ref_id="CVE-2010-1323" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1323.html"/>
        <description>MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to modify user-visible prompt text, modify a response to a Key Distribution Center (KDC), or forge a KRB-SAFE message via certain checksums that (1) are unkeyed or (2) use RC4 keys.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:34.776-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:34.093-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:00.351-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="krb5-libs is earlier than 0:1.6.1-36.el5_5.6" test_ref="oval:org.mitre.oval:tst:100100"/>
          <criterion comment="krb5-devel is earlier than 0:1.6.1-36.el5_5.6" test_ref="oval:org.mitre.oval:tst:99916"/>
          <criterion comment="krb5-server is earlier than 0:1.6.1-36.el5_5.6" test_ref="oval:org.mitre.oval:tst:100113"/>
          <criterion comment="krb5 is earlier than 0:1.6.1-36.el5_5.6" test_ref="oval:org.mitre.oval:tst:99128"/>
          <criterion comment="krb5-workstation is earlier than 0:1.6.1-36.el5_5.6" test_ref="oval:org.mitre.oval:tst:100066"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22249" version="120" class="patch">
      <metadata>
        <title>RHSA-2010:0489: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0489-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0489.html"/>
        <reference source="CVE" ref_id="CVE-2010-0840" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0840.html"/>
        <reference source="CVE" ref_id="CVE-2010-0841" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0841.html"/>
        <reference source="CVE" ref_id="CVE-2010-0842" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0842.html"/>
        <reference source="CVE" ref_id="CVE-2010-0843" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0843.html"/>
        <reference source="CVE" ref_id="CVE-2010-0844" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0844.html"/>
        <reference source="CVE" ref_id="CVE-2010-0846" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0846.html"/>
        <reference source="CVE" ref_id="CVE-2010-0847" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0847.html"/>
        <reference source="CVE" ref_id="CVE-2010-0848" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0848.html"/>
        <reference source="CVE" ref_id="CVE-2010-0849" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0849.html"/>
        <description>Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow in a decoding routine used by the JPEGImageDecoderImpl interface, which allows code execution via a crafted JPEG image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:22.429-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:33.801-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:00.137-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.11.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99410"/>
          <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.11.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99422"/>
          <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.11.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99376"/>
          <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.11.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98604"/>
          <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.11.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99508"/>
          <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.11.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99507"/>
          <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.11.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99579"/>
          <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.11.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99193"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22247" version="224" class="patch">
      <metadata>
        <title>RHSA-2010:0503: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0503-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0503.html"/>
        <reference source="CVE" ref_id="CVE-2010-1240" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1240.html"/>
        <reference source="CVE" ref_id="CVE-2010-1285" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1285.html"/>
        <reference source="CVE" ref_id="CVE-2010-1295" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1295.html"/>
        <reference source="CVE" ref_id="CVE-2010-1297" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1297.html"/>
        <reference source="CVE" ref_id="CVE-2010-2168" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2168.html"/>
        <reference source="CVE" ref_id="CVE-2010-2201" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2201.html"/>
        <reference source="CVE" ref_id="CVE-2010-2202" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2202.html"/>
        <reference source="CVE" ref_id="CVE-2010-2203" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2203.html"/>
        <reference source="CVE" ref_id="CVE-2010-2204" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2204.html"/>
        <reference source="CVE" ref_id="CVE-2010-2205" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2205.html"/>
        <reference source="CVE" ref_id="CVE-2010-2206" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2206.html"/>
        <reference source="CVE" ref_id="CVE-2010-2207" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2207.html"/>
        <reference source="CVE" ref_id="CVE-2010-2208" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2208.html"/>
        <reference source="CVE" ref_id="CVE-2010-2209" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2209.html"/>
        <reference source="CVE" ref_id="CVE-2010-2210" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2210.html"/>
        <reference source="CVE" ref_id="CVE-2010-2211" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2211.html"/>
        <reference source="CVE" ref_id="CVE-2010-2212" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2212.html"/>
        <description>Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a PDF file containing Flash content with a crafted #1023 (3FFh) tag, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, and CVE-2010-2211.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:51.432-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:33.191-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:59.744-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="acroread-plugin is earlier than 0:9.3.3-1.el5" test_ref="oval:org.mitre.oval:tst:98769"/>
          <criterion comment="acroread is earlier than 0:9.3.3-1.el5" test_ref="oval:org.mitre.oval:tst:99343"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22242" version="172" class="patch">
      <metadata>
        <title>RHSA-2010:0545: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0545-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0545.html"/>
        <reference source="CESA" ref_id="CESA-2010:0545"/>
        <reference source="CVE" ref_id="CVE-2010-0174" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0174.html"/>
        <reference source="CVE" ref_id="CVE-2010-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0175.html"/>
        <reference source="CVE" ref_id="CVE-2010-0176" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0176.html"/>
        <reference source="CVE" ref_id="CVE-2010-0177" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0177.html"/>
        <reference source="CVE" ref_id="CVE-2010-1197" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1197.html"/>
        <reference source="CVE" ref_id="CVE-2010-1198" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1198.html"/>
        <reference source="CVE" ref_id="CVE-2010-1199" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1199.html"/>
        <reference source="CVE" ref_id="CVE-2010-1200" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1200.html"/>
        <reference source="CVE" ref_id="CVE-2010-1205" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1205.html"/>
        <reference source="CVE" ref_id="CVE-2010-1211" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1211.html"/>
        <reference source="CVE" ref_id="CVE-2010-1214" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1214.html"/>
        <reference source="CVE" ref_id="CVE-2010-2753" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2753.html"/>
        <reference source="CVE" ref_id="CVE-2010-2754" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2754.html"/>
        <description>dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not properly suppress a script's URL in certain circumstances involving a redirect and an error message, which allows remote attackers to obtain sensitive information about script parameters via a crafted HTML document, related to the window.onerror handler.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:59.140-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:32.672-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:59.400-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-6.el5" test_ref="oval:org.mitre.oval:tst:98887"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22225" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0567: lvm2-cluster security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>lvm2-cluster</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0567-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0567.html"/>
        <reference source="CESA" ref_id="CESA-2010:0567"/>
        <reference source="CVE" ref_id="CVE-2010-2526" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2526.html"/>
        <description>The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:06.170-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:32.259-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:58.887-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="lvm2-cluster is earlier than 0:2.02.56-7.el5_5.4" test_ref="oval:org.mitre.oval:tst:99665"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22224" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0361: sudo security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0361-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0361.html"/>
        <reference source="CESA" ref_id="CESA-2010:0361"/>
        <reference source="CVE" ref_id="CVE-2010-1163" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1163.html"/>
        <description>The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary commands via a Trojan horse executable, as demonstrated using sudoedit, a different vulnerability than CVE-2010-0426.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:16.187-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:32.165-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:58.788-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="sudo is earlier than 0:1.7.2p1-6.el5_5" test_ref="oval:org.mitre.oval:tst:99423"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22220" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0742: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>postgresql</product>
          <product>postgresql84</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0742-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0742.html"/>
        <reference source="CESA" ref_id="CESA-2010:0742"/>
        <reference source="CVE" ref_id="CVE-2010-3433" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3433.html"/>
        <description>The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, as demonstrated by (1) redefining standard functions or (2) redefining operators, a different vulnerability than CVE-2010-1168, CVE-2010-1169, CVE-2010-1170, and CVE-2010-1447.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:49.233-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:31.908-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:57.929-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="postgresql84-tcl is earlier than 0:8.4.5-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99603"/>
          <criterion comment="postgresql84-docs is earlier than 0:8.4.5-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99576"/>
          <criterion comment="postgresql84-python is earlier than 0:8.4.5-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99565"/>
          <criterion comment="postgresql84-plpython is earlier than 0:8.4.5-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:98805"/>
          <criterion comment="postgresql84-server is earlier than 0:8.4.5-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99489"/>
          <criterion comment="postgresql84-test is earlier than 0:8.4.5-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99713"/>
          <criterion comment="postgresql84-libs is earlier than 0:8.4.5-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99777"/>
          <criterion comment="postgresql84-pltcl is earlier than 0:8.4.5-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99721"/>
          <criterion comment="postgresql84-plperl is earlier than 0:8.4.5-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99605"/>
          <criterion comment="postgresql84-devel is earlier than 0:8.4.5-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99516"/>
          <criterion comment="postgresql84 is earlier than 0:8.4.5-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99640"/>
          <criterion comment="postgresql84-contrib is earlier than 0:8.4.5-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99528"/>
          <criterion comment="postgresql-docs is earlier than 0:8.1.22-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99171"/>
          <criterion comment="postgresql-devel is earlier than 0:8.1.22-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:98927"/>
          <criterion comment="postgresql-test is earlier than 0:8.1.22-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99754"/>
          <criterion comment="postgresql-contrib is earlier than 0:8.1.22-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99512"/>
          <criterion comment="postgresql-libs is earlier than 0:8.1.22-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99389"/>
          <criterion comment="postgresql-tcl is earlier than 0:8.1.22-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99749"/>
          <criterion comment="postgresql is earlier than 0:8.1.22-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99317"/>
          <criterion comment="postgresql-python is earlier than 0:8.1.22-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99174"/>
          <criterion comment="postgresql-server is earlier than 0:8.1.22-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99564"/>
          <criterion comment="postgresql-pl is earlier than 0:8.1.22-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99552"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22217" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0811: cups security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0811-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0811.html"/>
        <reference source="CESA" ref_id="CESA-2010:0811"/>
        <reference source="CVE" ref_id="CVE-2010-2431" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2431.html"/>
        <reference source="CVE" ref_id="CVE-2010-2941" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2941.html"/>
        <description>ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:59.987-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:31.802-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:57.683-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="cups-lpd is earlier than 1:1.3.7-18.el5_5.8" test_ref="oval:org.mitre.oval:tst:99844"/>
          <criterion comment="cups-devel is earlier than 1:1.3.7-18.el5_5.8" test_ref="oval:org.mitre.oval:tst:99810"/>
          <criterion comment="cups-libs is earlier than 1:1.3.7-18.el5_5.8" test_ref="oval:org.mitre.oval:tst:99704"/>
          <criterion comment="cups is earlier than 1:1.3.7-18.el5_5.8" test_ref="oval:org.mitre.oval:tst:99582"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22215" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0697: samba security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0697-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0697.html"/>
        <reference source="CESA" ref_id="CESA-2010:0697"/>
        <reference source="CVE" ref_id="CVE-2010-3069" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3069.html"/>
        <description>Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file share.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:18.507-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:31.618-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:57.305-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libsmbclient is earlier than 0:3.0.33-3.29.el5_5.1" test_ref="oval:org.mitre.oval:tst:99647"/>
          <criterion comment="samba-client is earlier than 0:3.0.33-3.29.el5_5.1" test_ref="oval:org.mitre.oval:tst:99720"/>
          <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.29.el5_5.1" test_ref="oval:org.mitre.oval:tst:98866"/>
          <criterion comment="samba-common is earlier than 0:3.0.33-3.29.el5_5.1" test_ref="oval:org.mitre.oval:tst:99095"/>
          <criterion comment="samba is earlier than 0:3.0.33-3.29.el5_5.1" test_ref="oval:org.mitre.oval:tst:99459"/>
          <criterion comment="samba-swat is earlier than 0:3.0.33-3.29.el5_5.1" test_ref="oval:org.mitre.oval:tst:99652"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22211" version="81" class="patch">
      <metadata>
        <title>RHSA-2010:0578: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0578-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0578.html"/>
        <reference source="CESA" ref_id="CESA-2010:0578"/>
        <reference source="CVE" ref_id="CVE-2010-2498" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2498.html"/>
        <reference source="CVE" ref_id="CVE-2010-2499" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2499.html"/>
        <reference source="CVE" ref_id="CVE-2010-2500" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2500.html"/>
        <reference source="CVE" ref_id="CVE-2010-2519" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2519.html"/>
        <reference source="CVE" ref_id="CVE-2010-2527" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2527.html"/>
        <reference source="CVE" ref_id="CVE-2010-2541" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2541.html"/>
        <description>Buffer overflow in ftmulti.c in the ftmulti demo program in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:21.207-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:31.377-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:56.953-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="freetype is earlier than 0:2.2.1-25.el5_5" test_ref="oval:org.mitre.oval:tst:99596"/>
          <criterion comment="freetype-demos is earlier than 0:2.2.1-25.el5_5" test_ref="oval:org.mitre.oval:tst:99589"/>
          <criterion comment="freetype-devel is earlier than 0:2.2.1-25.el5_5" test_ref="oval:org.mitre.oval:tst:99622"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22207" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0998: kvm security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0998-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0998.html"/>
        <reference source="CVE" ref_id="CVE-2010-3881" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3881.html"/>
        <description>arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:09.556-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:31.195-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:56.598-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kvm-qemu-img is earlier than 0:83-164.el5_5.30" test_ref="oval:org.mitre.oval:tst:99175"/>
          <criterion comment="kvm is earlier than 0:83-164.el5_5.30" test_ref="oval:org.mitre.oval:tst:100015"/>
          <criterion comment="kmod-kvm is earlier than 0:83-164.el5_5.30" test_ref="oval:org.mitre.oval:tst:100004"/>
          <criterion comment="kvm-tools is earlier than 0:83-164.el5_5.30" test_ref="oval:org.mitre.oval:tst:100169"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22206" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0652: ImageMagick security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>ImageMagick</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0652-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0652.html"/>
        <reference source="CESA" ref_id="CESA-2010:0652"/>
        <reference source="CVE" ref_id="CVE-2009-1882" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1882.html"/>
        <description>Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:35.326-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:31.094-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:56.380-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="ImageMagick-c++-devel is earlier than 0:6.2.8.0-4.el5_5.2" test_ref="oval:org.mitre.oval:tst:99493"/>
          <criterion comment="ImageMagick-devel is earlier than 0:6.2.8.0-4.el5_5.2" test_ref="oval:org.mitre.oval:tst:99476"/>
          <criterion comment="ImageMagick-perl is earlier than 0:6.2.8.0-4.el5_5.2" test_ref="oval:org.mitre.oval:tst:99278"/>
          <criterion comment="ImageMagick is earlier than 0:6.2.8.0-4.el5_5.2" test_ref="oval:org.mitre.oval:tst:99612"/>
          <criterion comment="ImageMagick-c++ is earlier than 0:6.2.8.0-4.el5_5.2" test_ref="oval:org.mitre.oval:tst:99681"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22204" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0382: xorg-x11-server security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0382-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0382.html"/>
        <reference source="CESA" ref_id="CESA-2010:0382"/>
        <reference source="CVE" ref_id="CVE-2010-1166" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1166.html"/>
        <description>The fbComposite function in fbpict.c in the Render extension in the X server in X.Org X11R7.1 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted request, related to an incorrect macro definition.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:36.316-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:30.979-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:56.228-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.76.el5_5.1" test_ref="oval:org.mitre.oval:tst:98686"/>
          <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.76.el5_5.1" test_ref="oval:org.mitre.oval:tst:99043"/>
          <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.76.el5_5.1" test_ref="oval:org.mitre.oval:tst:98989"/>
          <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.76.el5_5.1" test_ref="oval:org.mitre.oval:tst:99056"/>
          <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.76.el5_5.1" test_ref="oval:org.mitre.oval:tst:99286"/>
          <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.76.el5_5.1" test_ref="oval:org.mitre.oval:tst:99353"/>
          <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.76.el5_5.1" test_ref="oval:org.mitre.oval:tst:99092"/>
          <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.76.el5_5.1" test_ref="oval:org.mitre.oval:tst:98914"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22203" version="111" class="patch">
      <metadata>
        <title>RHSA-2014:0139: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0139-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0139.html"/>
        <reference source="CESA" ref_id="CESA-2014:0139"/>
        <reference source="CVE" ref_id="CVE-2012-6152" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6152.html"/>
        <reference source="CVE" ref_id="CVE-2013-6477" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6477.html"/>
        <reference source="CVE" ref_id="CVE-2013-6478" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6478.html"/>
        <reference source="CVE" ref_id="CVE-2013-6479" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6479.html"/>
        <reference source="CVE" ref_id="CVE-2013-6481" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6481.html"/>
        <reference source="CVE" ref_id="CVE-2013-6482" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6482.html"/>
        <reference source="CVE" ref_id="CVE-2013-6483" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6483.html"/>
        <reference source="CVE" ref_id="CVE-2013-6484" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6484.html"/>
        <reference source="CVE" ref_id="CVE-2013-6485" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6485.html"/>
        <reference source="CVE" ref_id="CVE-2013-6487" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6487.html"/>
        <reference source="CVE" ref_id="CVE-2013-6489" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6489.html"/>
        <reference source="CVE" ref_id="CVE-2013-6490" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6490.html"/>
        <reference source="CVE" ref_id="CVE-2014-0020" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0020.html"/>
        <description>The IRC protocol plugin in libpurple in Pidgin before 2.10.8 does not validate argument counts, which allows remote IRC servers to cause a denial of service (application crash) via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:15.312-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:39.038-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:18.086-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22203 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:17.941-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:13.664-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22203 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:34.799-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:53.359-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpurple is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:100193"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:100391"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:100046"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:100258"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:99785"/>
            <criterion comment="finch is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:100061"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:100448"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:99911"/>
            <criterion comment="finch-devel is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:99966"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpurple is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100119"/>
            <criterion comment="pidgin-perl is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100321"/>
            <criterion comment="pidgin-docs is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100252"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100189"/>
            <criterion comment="pidgin-devel is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100505"/>
            <criterion comment="libpurple-perl is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100413"/>
            <criterion comment="finch is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100426"/>
            <criterion comment="libpurple-devel is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100512"/>
            <criterion comment="pidgin is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100487"/>
            <criterion comment="finch-devel is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100181"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22199" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0787: glibc security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0787-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0787.html"/>
        <reference source="CESA" ref_id="CESA-2010:0787"/>
        <reference source="CVE" ref_id="CVE-2010-3847" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3847.html"/>
        <description>elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:22.391-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:30.880-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:56.074-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="glibc-headers is earlier than 0:2.5-49.el5_5.6" test_ref="oval:org.mitre.oval:tst:99675"/>
          <criterion comment="glibc-common is earlier than 0:2.5-49.el5_5.6" test_ref="oval:org.mitre.oval:tst:98818"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-49.el5_5.6" test_ref="oval:org.mitre.oval:tst:99370"/>
          <criterion comment="glibc is earlier than 0:2.5-49.el5_5.6" test_ref="oval:org.mitre.oval:tst:99437"/>
          <criterion comment="nscd is earlier than 0:2.5-49.el5_5.6" test_ref="oval:org.mitre.oval:tst:99419"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-49.el5_5.6" test_ref="oval:org.mitre.oval:tst:98832"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22198" version="81" class="patch">
      <metadata>
        <title>RHSA-2011:1479: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1479-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1479.html"/>
        <reference source="CESA" ref_id="CESA-2011:1479"/>
        <reference source="CVE" ref_id="CVE-2011-1162" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1162.html"/>
        <reference source="CVE" ref_id="CVE-2011-1898" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1898.html"/>
        <reference source="CVE" ref_id="CVE-2011-2203" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2203.html"/>
        <reference source="CVE" ref_id="CVE-2011-2494" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2494.html"/>
        <reference source="CVE" ref_id="CVE-2011-3363" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3363.html"/>
        <reference source="CVE" ref_id="CVE-2011-4110" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4110.html"/>
        <description>The user_update function in security/keys/user_defined.c in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and kernel oops) via vectors related to a user-defined key and "updating a negative key into a fully instantiated key."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:43.625-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:30.599-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:55.282-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:98836"/>
          <criterion comment="kernel is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:98526"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:98817"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:98407"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:98843"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:98845"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:98746"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:98709"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:98885"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:98712"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:98549"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:98114"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22197" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0221: squid security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>squid</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0221-04" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0221.html"/>
        <reference source="CVE" ref_id="CVE-2009-2855" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2855.html"/>
        <reference source="CVE" ref_id="CVE-2010-0308" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0308.html"/>
        <description>lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:21.469-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:30.481-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:55.071-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="squid is earlier than 7:2.6.STABLE21-6.el5" test_ref="oval:org.mitre.oval:tst:99159"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22196" version="42" class="patch">
      <metadata>
        <title>RHSA-2010:0162: openssl security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0162-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0162.html"/>
        <reference source="CESA" ref_id="CESA-2010:0162"/>
        <reference source="CVE" ref_id="CVE-2009-3245" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3245.html"/>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html"/>
        <reference source="CVE" ref_id="CVE-2010-0433" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0433.html"/>
        <description>The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:08.770-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:30.311-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:54.783-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openssl is earlier than 0:0.9.8e-12.el5_4.6" test_ref="oval:org.mitre.oval:tst:98756"/>
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-12.el5_4.6" test_ref="oval:org.mitre.oval:tst:99266"/>
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-12.el5_4.6" test_ref="oval:org.mitre.oval:tst:99133"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22195" version="5" class="patch">
      <metadata>
        <title>RHSA-2011:1268: firefox security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1268-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1268.html"/>
        <reference source="CESA" ref_id="CESA-2011:1268"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

The RHSA-2011:1242 Firefox update rendered HTTPS certificates signed by a
certain Certificate Authority (CA) as untrusted, but made an exception for
a select few. This update removes that exception, rendering every HTTPS
certificate signed by that CA as untrusted. (BZ#735483)

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.22. After installing the update, Firefox must be
restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:10.882-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:30.237-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:54.511-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22195 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:40.192-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:46.621-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.22-1.el5_7" test_ref="oval:org.mitre.oval:tst:98144"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.22-1.el5_7" test_ref="oval:org.mitre.oval:tst:98450"/>
            <criterion comment="firefox is earlier than 0:3.6.22-1.el5_7" test_ref="oval:org.mitre.oval:tst:98348"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.22-1.el6_1" test_ref="oval:org.mitre.oval:tst:98413"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.22-1.el6_1" test_ref="oval:org.mitre.oval:tst:98050"/>
            <criterion comment="firefox is earlier than 0:3.6.22-1.el6_1" test_ref="oval:org.mitre.oval:tst:98522"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22193" version="68" class="patch">
      <metadata>
        <title>RHSA-2011:1341: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1341-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1341.html"/>
        <reference source="CESA" ref_id="CESA-2011:1341"/>
        <reference source="CVE" ref_id="CVE-2011-2372" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2372.html"/>
        <reference source="CVE" ref_id="CVE-2011-2995" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2995.html"/>
        <reference source="CVE" ref_id="CVE-2011-2998" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2998.html"/>
        <reference source="CVE" ref_id="CVE-2011-2999" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2999.html"/>
        <reference source="CVE" ref_id="CVE-2011-3000" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3000.html"/>
        <description>Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:50.422-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:30.009-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:54.145-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.23-1.el5_7" test_ref="oval:org.mitre.oval:tst:98580"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.23-1.el5_7" test_ref="oval:org.mitre.oval:tst:98437"/>
            <criterion comment="firefox is earlier than 0:3.6.23-2.el5_7" test_ref="oval:org.mitre.oval:tst:98592"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:3.6.23-2.el6_1" test_ref="oval:org.mitre.oval:tst:98221"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.23-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98338"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.23-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98441"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22189" version="122" class="patch">
      <metadata>
        <title>RHSA-2014:0097: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0097-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0097.html"/>
        <reference source="CESA" ref_id="CESA-2014:0097"/>
        <reference source="CVE" ref_id="CVE-2013-5878" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5878.html"/>
        <reference source="CVE" ref_id="CVE-2013-5884" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5884.html"/>
        <reference source="CVE" ref_id="CVE-2013-5896" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5896.html"/>
        <reference source="CVE" ref_id="CVE-2013-5907" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5907.html"/>
        <reference source="CVE" ref_id="CVE-2013-5910" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5910.html"/>
        <reference source="CVE" ref_id="CVE-2014-0368" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0368.html"/>
        <reference source="CVE" ref_id="CVE-2014-0373" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0373.html"/>
        <reference source="CVE" ref_id="CVE-2014-0376" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0376.html"/>
        <reference source="CVE" ref_id="CVE-2014-0411" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0411.html"/>
        <reference source="CVE" ref_id="CVE-2014-0416" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0416.html"/>
        <reference source="CVE" ref_id="CVE-2014-0422" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0422.html"/>
        <reference source="CVE" ref_id="CVE-2014-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0423.html"/>
        <reference source="CVE" ref_id="CVE-2014-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0428.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-28T12:16:52">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-11T14:03:36.709-05:00">DRAFT</status_change>
            <status_change date="2014-03-03T04:01:04.033-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:33.113-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22189 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:31:00.517-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:32:53.300-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:12.297-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:100218"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:100267"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:99398"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:100331"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:100042"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:99953"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:100233"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:99903"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:100373"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:99792"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22185" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0181: brltty security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>brltty</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0181-05" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0181.html"/>
        <reference source="CVE" ref_id="CVE-2008-3279" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3279.html"/>
        <description>Untrusted search path vulnerability in libbrlttybba.so in brltty 3.7.2 allows local users to gain privileges via a crafted library, related to an incorrect RPATH setting.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:44.095-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:29.724-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:53.474-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="brltty is earlier than 0:3.7.2-4.el5" test_ref="oval:org.mitre.oval:tst:99104"/>
          <criterion comment="brlapi is earlier than 0:0.4.1-4.el5" test_ref="oval:org.mitre.oval:tst:99079"/>
          <criterion comment="brlapi-devel is earlier than 0:0.4.1-4.el5" test_ref="oval:org.mitre.oval:tst:99277"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22183" version="172" class="patch">
      <metadata>
        <title>RHSA-2010:0130: java-1.5.0-ibm security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0130-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0130.html"/>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html"/>
        <reference source="CVE" ref_id="CVE-2010-0084" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0084.html"/>
        <reference source="CVE" ref_id="CVE-2010-0085" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0085.html"/>
        <reference source="CVE" ref_id="CVE-2010-0087" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0087.html"/>
        <reference source="CVE" ref_id="CVE-2010-0088" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0088.html"/>
        <reference source="CVE" ref_id="CVE-2010-0089" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0089.html"/>
        <reference source="CVE" ref_id="CVE-2010-0091" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0091.html"/>
        <reference source="CVE" ref_id="CVE-2010-0092" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0092.html"/>
        <reference source="CVE" ref_id="CVE-2010-0094" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0094.html"/>
        <reference source="CVE" ref_id="CVE-2010-0095" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0095.html"/>
        <reference source="CVE" ref_id="CVE-2010-0837" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0837.html"/>
        <reference source="CVE" ref_id="CVE-2010-0838" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0838.html"/>
        <reference source="CVE" ref_id="CVE-2010-0839" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0839.html"/>
        <description>Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:19.034-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:29.310-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:53.002-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.11.1-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:98547"/>
          <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.11.1-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:99254"/>
          <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.11.1-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:98962"/>
          <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.11.1-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:99120"/>
          <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.11.1-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:98857"/>
          <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.11.1-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:98840"/>
          <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.11.1-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:99113"/>
          <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.11.1-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:98750"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22179" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0348: kdebase security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kdebase</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0348-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0348.html"/>
        <reference source="CESA" ref_id="CESA-2010:0348"/>
        <reference source="CVE" ref_id="CVE-2010-0436" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0436.html"/>
        <description>Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 through 4.4.2 allows local users to change the permissions of arbitrary files, and consequently gain privileges, by blocking the removal of a certain directory that contains a control socket, related to improper interaction with ksm.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:15.174-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:29.221-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:52.894-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kdebase is earlier than 6:3.5.4-21.el5_5.1" test_ref="oval:org.mitre.oval:tst:98798"/>
          <criterion comment="kdebase-devel is earlier than 6:3.5.4-21.el5_5.1" test_ref="oval:org.mitre.oval:tst:99363"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22178" version="55" class="patch">
      <metadata>
        <title>RHSA-2010:0019: kernel security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0019-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0019.html"/>
        <reference source="CESA" ref_id="CESA-2010:0019"/>
        <reference source="CVE" ref_id="CVE-2007-4567" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4567.html"/>
        <reference source="CVE" ref_id="CVE-2009-4536" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4536.html"/>
        <reference source="CVE" ref_id="CVE-2009-4537" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4537.html"/>
        <reference source="CVE" ref_id="CVE-2009-4538" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4538.html"/>
        <description>drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a related issue to CVE-2009-4537.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:26.117-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:29.041-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:52.663-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:99083"/>
          <criterion comment="kernel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:98830"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:98741"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:98912"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:98662"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:99004"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:99081"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:98930"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:99011"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:98528"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:98772"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:98874"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22173" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0044: pidgin security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0044-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0044.html"/>
        <reference source="CESA" ref_id="CESA-2010:0044"/>
        <reference source="CVE" ref_id="CVE-2010-0013" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0013.html"/>
        <description>Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122.  NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:10.038-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:28.943-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:52.517-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libpurple is earlier than 0:2.6.5-1.el5" test_ref="oval:org.mitre.oval:tst:98872"/>
          <criterion comment="finch is earlier than 0:2.6.5-1.el5" test_ref="oval:org.mitre.oval:tst:98831"/>
          <criterion comment="libpurple-perl is earlier than 0:2.6.5-1.el5" test_ref="oval:org.mitre.oval:tst:99123"/>
          <criterion comment="pidgin is earlier than 0:2.6.5-1.el5" test_ref="oval:org.mitre.oval:tst:98268"/>
          <criterion comment="libpurple-devel is earlier than 0:2.6.5-1.el5" test_ref="oval:org.mitre.oval:tst:98965"/>
          <criterion comment="pidgin-devel is earlier than 0:2.6.5-1.el5" test_ref="oval:org.mitre.oval:tst:98786"/>
          <criterion comment="finch-devel is earlier than 0:2.6.5-1.el5" test_ref="oval:org.mitre.oval:tst:98937"/>
          <criterion comment="pidgin-perl is earlier than 0:2.6.5-1.el5" test_ref="oval:org.mitre.oval:tst:98828"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.6.5-1.el5" test_ref="oval:org.mitre.oval:tst:99160"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22172" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0273: curl security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>curl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0273-05" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0273.html"/>
        <reference source="CVE" ref_id="CVE-2010-0734" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0734.html"/>
        <description>content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact by sending crafted compressed data to an application that relies on the intended data-length limit.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:08.314-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:28.797-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:52.392-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="curl is earlier than 0:7.15.5-9.el5" test_ref="oval:org.mitre.oval:tst:99291"/>
          <criterion comment="curl-devel is earlier than 0:7.15.5-9.el5" test_ref="oval:org.mitre.oval:tst:99290"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22169" version="55" class="patch">
      <metadata>
        <title>RHSA-2010:0088: kvm security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0088-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0088.html"/>
        <reference source="CESA" ref_id="CESA-2010:0088"/>
        <reference source="CVE" ref_id="CVE-2010-0297" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0297.html"/>
        <reference source="CVE" ref_id="CVE-2010-0298" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0298.html"/>
        <reference source="CVE" ref_id="CVE-2010-0306" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0306.html"/>
        <reference source="CVE" ref_id="CVE-2010-0309" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0309.html"/>
        <description>The pit_ioport_read function in the Programmable Interval Timer (PIT) emulation in i8254.c in KVM 83 does not properly use the pit_state data structure, which allows guest OS users to cause a denial of service (host OS crash or hang) by attempting to read the /dev/port file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:36.661-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:28.653-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:52.181-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kvm-qemu-img is earlier than 0:83-105.el5_4.22" test_ref="oval:org.mitre.oval:tst:98653"/>
          <criterion comment="kvm is earlier than 0:83-105.el5_4.22" test_ref="oval:org.mitre.oval:tst:98623"/>
          <criterion comment="kmod-kvm is earlier than 0:83-105.el5_4.22" test_ref="oval:org.mitre.oval:tst:99141"/>
          <criterion comment="kvm-tools is earlier than 0:83-105.el5_4.22" test_ref="oval:org.mitre.oval:tst:99098"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22164" version="55" class="patch">
      <metadata>
        <title>RHSA-2010:0819: pam security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>pam</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0819-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0819.html"/>
        <reference source="CESA" ref_id="CESA-2010:0819"/>
        <reference source="CVE" ref_id="CVE-2010-3316" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3316.html"/>
        <reference source="CVE" ref_id="CVE-2010-3435" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3435.html"/>
        <reference source="CVE" ref_id="CVE-2010-3853" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3853.html"/>
        <reference source="CVE" ref_id="CVE-2010-4707" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4707.html"/>
        <description>The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:09.188-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:28.309-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:51.703-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="pam-devel is earlier than 0:0.99.6.2-6.el5_5.2" test_ref="oval:org.mitre.oval:tst:99771"/>
          <criterion comment="pam is earlier than 0:0.99.6.2-6.el5_5.2" test_ref="oval:org.mitre.oval:tst:99700"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22161" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1109: foomatic security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>foomatic</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1109-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1109.html"/>
        <reference source="CESA" ref_id="CESA-2011:1109"/>
        <reference source="CVE" ref_id="CVE-2011-2697" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2697.html"/>
        <description>foomatic-rip-hplip in HP Linux Imaging and Printing (HPLIP) 3.11.5 allows remote attackers to execute arbitrary code via a crafted *FoomaticRIPCommandLine field in a .ppd file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:29.573-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:28.140-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:51.511-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="foomatic is earlier than 0:3.0.2-38.3.el5_7.1" test_ref="oval:org.mitre.oval:tst:98263"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22159" version="81" class="patch">
      <metadata>
        <title>RHSA-2010:0839: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0839-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0839.html"/>
        <reference source="CESA" ref_id="CESA-2010:0839"/>
        <reference source="CVE" ref_id="CVE-2010-3066" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3066.html"/>
        <reference source="CVE" ref_id="CVE-2010-3067" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3067.html"/>
        <reference source="CVE" ref_id="CVE-2010-3078" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3078.html"/>
        <reference source="CVE" ref_id="CVE-2010-3086" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3086.html"/>
        <reference source="CVE" ref_id="CVE-2010-3448" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3448.html"/>
        <reference source="CVE" ref_id="CVE-2010-3477" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3477.html"/>
        <description>The tcf_act_police_dump function in net/sched/act_police.c in the actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc4 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel memory via vectors involving a dump operation.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-2942.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:22.047-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:27.930-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:51.225-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:99853"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:99660"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:99717"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:98909"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:99632"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:99569"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:99739"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:99803"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:99168"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:99683"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:99845"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:98968"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22152" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0141: tar security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>tar</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0141-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0141.html"/>
        <reference source="CESA" ref_id="CESA-2010:0141"/>
        <reference source="CVE" ref_id="CVE-2007-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4476.html"/>
        <reference source="CVE" ref_id="CVE-2010-0624" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0624.html"/>
        <description>Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:11.183-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:27.598-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:50.752-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="tar is earlier than 2:1.15.1-23.0.1.el5_4.2" test_ref="oval:org.mitre.oval:tst:99067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22151" version="94" class="patch">
      <metadata>
        <title>RHSA-2011:1845: tomcat5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>tomcat5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1845-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1845.html"/>
        <reference source="CESA" ref_id="CESA-2011:1845"/>
        <reference source="CVE" ref_id="CVE-2010-3718" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3718.html"/>
        <reference source="CVE" ref_id="CVE-2011-0013" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0013.html"/>
        <reference source="CVE" ref_id="CVE-2011-1184" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1184.html"/>
        <reference source="CVE" ref_id="CVE-2011-2204" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2204.html"/>
        <reference source="CVE" ref_id="CVE-2011-5062" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-5062.html"/>
        <reference source="CVE" ref_id="CVE-2011-5063" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-5063.html"/>
        <reference source="CVE" ref_id="CVE-2011-5064" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-5064.html"/>
        <description>DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:20.944-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:27.341-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:50.419-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:98876"/>
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:98009"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:98869"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:98855"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:98995"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:98559"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:99005"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:98719"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:98722"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:98837"/>
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:98392"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22150" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1324: qt4 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>qt4</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1324-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1324.html"/>
        <reference source="CESA" ref_id="CESA-2011:1324"/>
        <reference source="CVE" ref_id="CVE-2007-0242" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0242.html"/>
        <reference source="CVE" ref_id="CVE-2011-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3193.html"/>
        <description>Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:40.772-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:27.158-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:50.245-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="qt4-odbc is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98333"/>
          <criterion comment="qt4-devel is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:97602"/>
          <criterion comment="qt4-postgresql is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98146"/>
          <criterion comment="qt4 is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98500"/>
          <criterion comment="qt4-sqlite is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:97652"/>
          <criterion comment="qt4-mysql is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98195"/>
          <criterion comment="qt4-doc is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:97857"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22149" version="107" class="patch">
      <metadata>
        <title>RHSA-2011:1159: java-1.4.2-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.4.2-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1159-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1159.html"/>
        <reference source="CVE" ref_id="CVE-2011-0311" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0311.html"/>
        <reference source="CVE" ref_id="CVE-2011-0802" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0802.html"/>
        <reference source="CVE" ref_id="CVE-2011-0814" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0814.html"/>
        <reference source="CVE" ref_id="CVE-2011-0862" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0862.html"/>
        <reference source="CVE" ref_id="CVE-2011-0865" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0865.html"/>
        <reference source="CVE" ref_id="CVE-2011-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0867.html"/>
        <reference source="CVE" ref_id="CVE-2011-0871" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0871.html"/>
        <reference source="CVE" ref_id="CVE-2011-3387" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3387.html"/>
        <description>The class file parser in IBM Java 1.4.2 SR13 FP9 allows remote authenticated users to cause a denial of service (memory consumption or an infinite loop) via a crafted attribute length field in a class file, related to validation of a length field at the wrong time, a different vulnerability than CVE-2011-0311.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:46.102-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:26.792-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:49.893-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.10-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98235"/>
          <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.10-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97994"/>
          <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.10-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97985"/>
          <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.10-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98190"/>
          <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.10-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98226"/>
          <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.10-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97937"/>
          <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.10-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97943"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22146" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1851: krb5 security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1851-02" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1851.html"/>
        <reference source="CESA" ref_id="CESA-2011:1851"/>
        <reference source="CVE" ref_id="CVE-2011-4862" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4862.html"/>
        <description>Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:14.480-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:26.654-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:49.781-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="krb5-libs is earlier than 0:1.6.1-63.el5_7" test_ref="oval:org.mitre.oval:tst:98842"/>
          <criterion comment="krb5-devel is earlier than 0:1.6.1-63.el5_7" test_ref="oval:org.mitre.oval:tst:98940"/>
          <criterion comment="krb5-server is earlier than 0:1.6.1-63.el5_7" test_ref="oval:org.mitre.oval:tst:98925"/>
          <criterion comment="krb5 is earlier than 0:1.6.1-63.el5_7" test_ref="oval:org.mitre.oval:tst:98288"/>
          <criterion comment="krb5-workstation is earlier than 0:1.6.1-63.el5_7" test_ref="oval:org.mitre.oval:tst:98560"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.6.1-63.el5_7" test_ref="oval:org.mitre.oval:tst:98788"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22145" version="107" class="patch">
      <metadata>
        <title>RHSA-2010:0112: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0112-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0112.html"/>
        <reference source="CESA" ref_id="CESA-2010:0112"/>
        <reference source="CVE" ref_id="CVE-2009-1571" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1571.html"/>
        <reference source="CVE" ref_id="CVE-2009-3988" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3988.html"/>
        <reference source="CVE" ref_id="CVE-2010-0159" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0159.html"/>
        <reference source="CVE" ref_id="CVE-2010-0160" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0160.html"/>
        <reference source="CVE" ref_id="CVE-2010-0162" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0162.html"/>
        <reference source="CVE" ref_id="CVE-2010-0167" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0167.html"/>
        <reference source="CVE" ref_id="CVE-2010-0169" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0169.html"/>
        <reference source="CVE" ref_id="CVE-2010-0171" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0171.html"/>
        <description>Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allow remote attackers to perform cross-origin keystroke capture, and possibly conduct cross-site scripting (XSS) attacks, by using the addEventListener and setTimeout functions in conjunction with a wrapped object.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-3736.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:31.620-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:26.282-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:49.472-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:99068"/>
          <criterion comment="xulrunner is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:99147"/>
          <criterion comment="xulrunner-devel is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:98875"/>
          <criterion comment="firefox is earlier than 0:3.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:99012"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22144" version="81" class="patch">
      <metadata>
        <title>RHSA-2010:0332: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0332-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0332.html"/>
        <reference source="CVE" ref_id="CVE-2010-0174" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0174.html"/>
        <reference source="CVE" ref_id="CVE-2010-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0175.html"/>
        <reference source="CVE" ref_id="CVE-2010-0176" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0176.html"/>
        <reference source="CVE" ref_id="CVE-2010-0177" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0177.html"/>
        <reference source="CVE" ref_id="CVE-2010-0178" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0178.html"/>
        <reference source="CVE" ref_id="CVE-2010-0179" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0179.html"/>
        <description>Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:13.575-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:25.992-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:49.196-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:98674"/>
          <criterion comment="xulrunner is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:98894"/>
          <criterion comment="xulrunner-devel is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:99163"/>
          <criterion comment="firefox is earlier than 0:3.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:98877"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22143" version="81" class="patch">
      <metadata>
        <title>RHSA-2010:0519: libtiff security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0519-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0519.html"/>
        <reference source="CESA" ref_id="CESA-2010:0519"/>
        <reference source="CVE" ref_id="CVE-2010-1411" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1411.html"/>
        <reference source="CVE" ref_id="CVE-2010-2481" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2481.html"/>
        <reference source="CVE" ref_id="CVE-2010-2483" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2483.html"/>
        <reference source="CVE" ref_id="CVE-2010-2595" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2595.html"/>
        <reference source="CVE" ref_id="CVE-2010-2597" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2597.html"/>
        <reference source="CVE" ref_id="CVE-2010-4665" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4665.html"/>
        <description>Integer overflow in the ReadDirectory function in tiffdump.c in tiffdump in LibTIFF before 3.9.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF file containing a directory data structure with many directory entries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:31.537-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:25.670-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:48.926-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libtiff is earlier than 0:3.8.2-7.el5_5.5" test_ref="oval:org.mitre.oval:tst:99465"/>
          <criterion comment="libtiff-devel is earlier than 0:3.8.2-7.el5_5.5" test_ref="oval:org.mitre.oval:tst:99485"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22142" version="42" class="patch">
      <metadata>
        <title>RHSA-2010:0430: postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>postgresql84</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0430-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0430.html"/>
        <reference source="CESA" ref_id="CESA-2010:0430"/>
        <reference source="CVE" ref_id="CVE-2010-1169" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1169.html"/>
        <reference source="CVE" ref_id="CVE-2010-1170" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1170.html"/>
        <reference source="CVE" ref_id="CVE-2010-1975" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1975.html"/>
        <description>PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, and 8.4 before 8.4.4 does not properly check privileges during certain RESET ALL operations, which allows remote authenticated users to remove arbitrary parameter settings via a (1) ALTER USER or (2) ALTER DATABASE statement.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:09.184-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:25.354-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:48.732-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="postgresql84-tcl is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99001"/>
          <criterion comment="postgresql84-docs is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99186"/>
          <criterion comment="postgresql84-python is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99337"/>
          <criterion comment="postgresql84-plpython is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:98958"/>
          <criterion comment="postgresql84-test is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99253"/>
          <criterion comment="postgresql84-libs is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99409"/>
          <criterion comment="postgresql84-server is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:98822"/>
          <criterion comment="postgresql84-pltcl is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99393"/>
          <criterion comment="postgresql84-plperl is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99323"/>
          <criterion comment="postgresql84-devel is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:98637"/>
          <criterion comment="postgresql84 is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99088"/>
          <criterion comment="postgresql84-contrib is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99288"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22141" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0518: scsi-target-utils security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>scsi-target-utils</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0518-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0518.html"/>
        <reference source="CESA" ref_id="CESA-2010:0518"/>
        <reference source="CVE" ref_id="CVE-2010-2221" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2221.html"/>
        <description>Multiple buffer overflows in the iSNS implementation in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) before 1.0.6, (2) iSCSI Enterprise Target (aka iscsitarget or IET) 1.4.20.1 and earlier, and (3) Generic SCSI Target Subsystem for Linux (aka SCST or iscsi-scst) 1.0.1.1 and earlier allow remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via (a) a long iSCSI Name string in an SCN message or (b) an invalid PDU.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:07.952-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:25.255-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:48.608-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="scsi-target-utils is earlier than 0:0.0-6.20091205snap.el5_5.3" test_ref="oval:org.mitre.oval:tst:99571"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22140" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0475: sudo security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0475-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0475.html"/>
        <reference source="CESA" ref_id="CESA-2010:0475"/>
        <reference source="CVE" ref_id="CVE-2010-1646" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1646.html"/>
        <description>The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:47.666-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:25.159-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:48.518-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="sudo is earlier than 0:1.7.2p1-7.el5_5" test_ref="oval:org.mitre.oval:tst:99320"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22138" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1815: icu security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>icu</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1815-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1815.html"/>
        <reference source="CESA" ref_id="CESA-2011:1815"/>
        <reference source="CVE" ref_id="CVE-2011-4599" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4599.html"/>
        <description>Stack-based buffer overflow in the _canonicalize function in common/uloc.c in International Components for Unicode (ICU) before 49.1 allows remote attackers to execute arbitrary code via a crafted locale ID that is not properly handled during variant canonicalization.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:44.756-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:24.885-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:48.261-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libicu-devel is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:98771"/>
            <criterion comment="libicu-doc is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:98751"/>
            <criterion comment="libicu is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:98898"/>
            <criterion comment="icu is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:98424"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libicu-devel is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:98896"/>
            <criterion comment="libicu-doc is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:98133"/>
            <criterion comment="libicu is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:98443"/>
            <criterion comment="icu is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:98768"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22136" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0114: acroread security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0114-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0114.html"/>
        <reference source="CVE" ref_id="CVE-2010-0186" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0186.html"/>
        <reference source="CVE" ref_id="CVE-2010-0188" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0188.html"/>
        <description>Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:01.165-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:24.785-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:48.146-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="acroread-plugin is earlier than 0:9.3.1-1.el5" test_ref="oval:org.mitre.oval:tst:98616"/>
          <criterion comment="acroread is earlier than 0:9.3.1-1.el5" test_ref="oval:org.mitre.oval:tst:98975"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22134" version="42" class="patch">
      <metadata>
        <title>RHSA-2010:0442: mysql security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0442-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0442.html"/>
        <reference source="CESA" ref_id="CESA-2010:0442"/>
        <reference source="CVE" ref_id="CVE-2010-1626" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1626.html"/>
        <reference source="CVE" ref_id="CVE-2010-1848" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1848.html"/>
        <reference source="CVE" ref_id="CVE-2010-1850" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1850.html"/>
        <description>Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELD_LIST command with a long table name.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:27.054-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:24.661-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:47.972-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mysql-test is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:99356"/>
          <criterion comment="mysql is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:99082"/>
          <criterion comment="mysql-server is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:99446"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:99226"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:99138"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22133" version="549" class="patch">
      <metadata>
        <title>RHSA-2011:1434: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1434-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1434.html"/>
        <reference source="CVE" ref_id="CVE-2011-2094" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2094.html"/>
        <reference source="CVE" ref_id="CVE-2011-2095" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2095.html"/>
        <reference source="CVE" ref_id="CVE-2011-2096" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2096.html"/>
        <reference source="CVE" ref_id="CVE-2011-2097" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2097.html"/>
        <reference source="CVE" ref_id="CVE-2011-2098" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2098.html"/>
        <reference source="CVE" ref_id="CVE-2011-2099" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2099.html"/>
        <reference source="CVE" ref_id="CVE-2011-2101" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2101.html"/>
        <reference source="CVE" ref_id="CVE-2011-2104" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2104.html"/>
        <reference source="CVE" ref_id="CVE-2011-2105" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2105.html"/>
        <reference source="CVE" ref_id="CVE-2011-2107" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2107.html"/>
        <reference source="CVE" ref_id="CVE-2011-2130" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2130.html"/>
        <reference source="CVE" ref_id="CVE-2011-2134" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2134.html"/>
        <reference source="CVE" ref_id="CVE-2011-2135" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2135.html"/>
        <reference source="CVE" ref_id="CVE-2011-2136" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2136.html"/>
        <reference source="CVE" ref_id="CVE-2011-2137" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2137.html"/>
        <reference source="CVE" ref_id="CVE-2011-2138" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2138.html"/>
        <reference source="CVE" ref_id="CVE-2011-2139" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2139.html"/>
        <reference source="CVE" ref_id="CVE-2011-2140" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2140.html"/>
        <reference source="CVE" ref_id="CVE-2011-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2414.html"/>
        <reference source="CVE" ref_id="CVE-2011-2415" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2415.html"/>
        <reference source="CVE" ref_id="CVE-2011-2416" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2416.html"/>
        <reference source="CVE" ref_id="CVE-2011-2417" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2417.html"/>
        <reference source="CVE" ref_id="CVE-2011-2424" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2424.html"/>
        <reference source="CVE" ref_id="CVE-2011-2425" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2425.html"/>
        <reference source="CVE" ref_id="CVE-2011-2426" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2426.html"/>
        <reference source="CVE" ref_id="CVE-2011-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2427.html"/>
        <reference source="CVE" ref_id="CVE-2011-2428" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2428.html"/>
        <reference source="CVE" ref_id="CVE-2011-2429" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2429.html"/>
        <reference source="CVE" ref_id="CVE-2011-2430" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2430.html"/>
        <reference source="CVE" ref_id="CVE-2011-2431" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2431.html"/>
        <reference source="CVE" ref_id="CVE-2011-2432" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2432.html"/>
        <reference source="CVE" ref_id="CVE-2011-2433" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2433.html"/>
        <reference source="CVE" ref_id="CVE-2011-2434" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2434.html"/>
        <reference source="CVE" ref_id="CVE-2011-2435" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2435.html"/>
        <reference source="CVE" ref_id="CVE-2011-2436" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2436.html"/>
        <reference source="CVE" ref_id="CVE-2011-2437" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2437.html"/>
        <reference source="CVE" ref_id="CVE-2011-2438" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2438.html"/>
        <reference source="CVE" ref_id="CVE-2011-2439" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2439.html"/>
        <reference source="CVE" ref_id="CVE-2011-2440" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2440.html"/>
        <reference source="CVE" ref_id="CVE-2011-2442" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2442.html"/>
        <reference source="CVE" ref_id="CVE-2011-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2444.html"/>
        <reference source="CVE" ref_id="CVE-2011-4374" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4374.html"/>
        <description>Integer overflow in Adobe Reader 9.x before 9.4.6 on Linux allows attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:05.688-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:23.624-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:46.895-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.4.6-1.el5" test_ref="oval:org.mitre.oval:tst:97774"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.6-1.el5" test_ref="oval:org.mitre.oval:tst:98628"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.4.6-1.el6" test_ref="oval:org.mitre.oval:tst:98469"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.6-1.el6" test_ref="oval:org.mitre.oval:tst:98773"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22132" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0362: scsi-target-utils security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>scsi-target-utils</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0362-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0362.html"/>
        <reference source="CESA" ref_id="CESA-2010:0362"/>
        <reference source="CVE" ref_id="CVE-2010-0743" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0743.html"/>
        <description>Multiple format string vulnerabilities in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) 1.0.3, 0.9.5, and earlier and (2) iSCSI Enterprise Target (aka iscsitarget) 0.4.16 allow remote attackers to cause a denial of service (tgtd daemon crash) or possibly have unspecified other impact via vectors that involve the isns_attr_query and qry_rsp_handle functions, and are related to (a) client appearance and (b) client disappearance messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:54.864-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:23.543-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:46.816-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="scsi-target-utils is earlier than 0:0.0-6.20091205snap.el5_5.2" test_ref="oval:org.mitre.oval:tst:99338"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22131" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0659: httpd security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0659-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0659.html"/>
        <reference source="CESA" ref_id="CESA-2010:0659"/>
        <reference source="CVE" ref_id="CVE-2010-1452" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1452.html"/>
        <reference source="CVE" ref_id="CVE-2010-2791" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2791.html"/>
        <description>mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a response from a persistent connection, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request.  NOTE: this is the same issue as CVE-2010-2068, but for a different OS and set of affected versions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:34.499-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:23.435-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:46.628-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="httpd-manual is earlier than 0:2.2.3-43.el5_5.3" test_ref="oval:org.mitre.oval:tst:99627"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.3-43.el5_5.3" test_ref="oval:org.mitre.oval:tst:99244"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.3-43.el5_5.3" test_ref="oval:org.mitre.oval:tst:99468"/>
          <criterion comment="httpd is earlier than 0:2.2.3-43.el5_5.3" test_ref="oval:org.mitre.oval:tst:99686"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22125" version="94" class="patch">
      <metadata>
        <title>RHSA-2011:1087: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1087-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1087.html"/>
        <reference source="CVE" ref_id="CVE-2011-0802" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0802.html"/>
        <reference source="CVE" ref_id="CVE-2011-0814" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0814.html"/>
        <reference source="CVE" ref_id="CVE-2011-0862" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0862.html"/>
        <reference source="CVE" ref_id="CVE-2011-0865" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0865.html"/>
        <reference source="CVE" ref_id="CVE-2011-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0867.html"/>
        <reference source="CVE" ref_id="CVE-2011-0871" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0871.html"/>
        <reference source="CVE" ref_id="CVE-2011-0873" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0873.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, and 5.0 Update 29 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:18.042-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:22.970-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:45.991-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97848"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97344"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98141"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98281"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98115"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97695"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97844"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98207"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98174"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97523"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98329"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98335"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98113"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97576"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98158"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22124" version="380" class="patch">
      <metadata>
        <title>RHSA-2010:0770: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0770-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0770.html"/>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html"/>
        <reference source="CVE" ref_id="CVE-2010-1321" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1321.html"/>
        <reference source="CVE" ref_id="CVE-2010-3541" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3541.html"/>
        <reference source="CVE" ref_id="CVE-2010-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3548.html"/>
        <reference source="CVE" ref_id="CVE-2010-3549" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3549.html"/>
        <reference source="CVE" ref_id="CVE-2010-3550" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3550.html"/>
        <reference source="CVE" ref_id="CVE-2010-3551" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3551.html"/>
        <reference source="CVE" ref_id="CVE-2010-3552" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3552.html"/>
        <reference source="CVE" ref_id="CVE-2010-3553" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3553.html"/>
        <reference source="CVE" ref_id="CVE-2010-3554" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3554.html"/>
        <reference source="CVE" ref_id="CVE-2010-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3555.html"/>
        <reference source="CVE" ref_id="CVE-2010-3556" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3556.html"/>
        <reference source="CVE" ref_id="CVE-2010-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3557.html"/>
        <reference source="CVE" ref_id="CVE-2010-3558" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3558.html"/>
        <reference source="CVE" ref_id="CVE-2010-3559" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3559.html"/>
        <reference source="CVE" ref_id="CVE-2010-3560" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3560.html"/>
        <reference source="CVE" ref_id="CVE-2010-3561" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3561.html"/>
        <reference source="CVE" ref_id="CVE-2010-3562" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3562.html"/>
        <reference source="CVE" ref_id="CVE-2010-3563" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3563.html"/>
        <reference source="CVE" ref_id="CVE-2010-3565" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3565.html"/>
        <reference source="CVE" ref_id="CVE-2010-3566" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3566.html"/>
        <reference source="CVE" ref_id="CVE-2010-3567" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3567.html"/>
        <reference source="CVE" ref_id="CVE-2010-3568" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3568.html"/>
        <reference source="CVE" ref_id="CVE-2010-3569" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3569.html"/>
        <reference source="CVE" ref_id="CVE-2010-3570" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3570.html"/>
        <reference source="CVE" ref_id="CVE-2010-3571" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3571.html"/>
        <reference source="CVE" ref_id="CVE-2010-3572" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3572.html"/>
        <reference source="CVE" ref_id="CVE-2010-3573" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3573.html"/>
        <reference source="CVE" ref_id="CVE-2010-3574" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3574.html"/>
        <description>Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable downstream vendor that HttpURLConnection does not properly check for the allowHttpTrace permission, which allows untrusted code to perform HTTP TRACE requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:11.505-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:22.306-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:45.140-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.22-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99455"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.22-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99676"/>
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.22-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99716"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.22-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99478"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.22-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99788"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.22-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99500"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22123" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1392: httpd security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1392-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1392.html"/>
        <reference source="CESA" ref_id="CESA-2011:1392"/>
        <reference source="CVE" ref_id="CVE-2011-3368" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3368.html"/>
        <description>The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:26.047-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:22.233-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:45.045-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="httpd-manual is earlier than 0:2.2.3-53.el5_7.3" test_ref="oval:org.mitre.oval:tst:98002"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.3-53.el5_7.3" test_ref="oval:org.mitre.oval:tst:98446"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.3-53.el5_7.3" test_ref="oval:org.mitre.oval:tst:98570"/>
          <criterion comment="httpd is earlier than 0:2.2.3-53.el5_7.3" test_ref="oval:org.mitre.oval:tst:98244"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22121" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0061: gzip security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gzip</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0061-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0061.html"/>
        <reference source="CESA" ref_id="CESA-2010:0061"/>
        <reference source="CVE" ref_id="CVE-2010-0001" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0001.html"/>
        <description>Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:43.907-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:22.152-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:44.930-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="gzip is earlier than 0:1.3.5-11.el5_4.1" test_ref="oval:org.mitre.oval:tst:98178"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22120" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0615: libvirt security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0615-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0615.html"/>
        <reference source="CESA" ref_id="CESA-2010:0615"/>
        <reference source="CVE" ref_id="CVE-2010-2239" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2239.html"/>
        <reference source="CVE" ref_id="CVE-2010-2242" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2242.html"/>
        <description>Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended access restrictions by leveraging IP address and source-port values, as demonstrated by copying and deleting an NFS directory tree.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:33.656-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:22.059-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:44.772-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libvirt-devel is earlier than 0:0.6.3-33.el5_5.3" test_ref="oval:org.mitre.oval:tst:99555"/>
          <criterion comment="libvirt is earlier than 0:0.6.3-33.el5_5.3" test_ref="oval:org.mitre.oval:tst:99693"/>
          <criterion comment="libvirt-python is earlier than 0:0.6.3-33.el5_5.3" test_ref="oval:org.mitre.oval:tst:99548"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22119" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0122: sudo security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0122-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0122.html"/>
        <reference source="CESA" ref_id="CESA-2010:0122"/>
        <reference source="CVE" ref_id="CVE-2010-0426" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0426.html"/>
        <reference source="CVE" ref_id="CVE-2010-0427" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0427.html"/>
        <description>sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not properly set group memberships, which allows local users to gain privileges via a sudo command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:37.132-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:21.956-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:44.656-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="sudo is earlier than 0:1.6.9p17-6.el5_4" test_ref="oval:org.mitre.oval:tst:98948"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22116" version="94" class="patch">
      <metadata>
        <title>RHSA-2011:1478: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1478-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1478.html"/>
        <reference source="CVE" ref_id="CVE-2011-3545" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3545.html"/>
        <reference source="CVE" ref_id="CVE-2011-3547" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3547.html"/>
        <reference source="CVE" ref_id="CVE-2011-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3548.html"/>
        <reference source="CVE" ref_id="CVE-2011-3549" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3549.html"/>
        <reference source="CVE" ref_id="CVE-2011-3552" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3552.html"/>
        <reference source="CVE" ref_id="CVE-2011-3554" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3554.html"/>
        <reference source="CVE" ref_id="CVE-2011-3556" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3556.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to RMI.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:37.349-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:21.630-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:44.297-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98297"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98754"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98475"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98775"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98729"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97885"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98668"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98657"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98763"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98345"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97910"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98861"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98667"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98598"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98324"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22115" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0126: kvm security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0126-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0126.html"/>
        <reference source="CESA" ref_id="CESA-2010:0126"/>
        <reference source="CVE" ref_id="CVE-2009-3722" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3722.html"/>
        <reference source="CVE" ref_id="CVE-2010-0419" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0419.html"/>
        <description>The x86 emulator in KVM 83, when a guest is configured for Symmetric Multiprocessing (SMP), does not properly restrict writing of segment selectors to segment registers, which might allow guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region, and replacing an instruction in between emulator entry and instruction fetch.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:03.702-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:21.525-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:44.165-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kvm-qemu-img is earlier than 0:83-105.el5_4.27" test_ref="oval:org.mitre.oval:tst:99185"/>
          <criterion comment="kvm is earlier than 0:83-105.el5_4.27" test_ref="oval:org.mitre.oval:tst:99134"/>
          <criterion comment="kmod-kvm is earlier than 0:83-105.el5_4.27" test_ref="oval:org.mitre.oval:tst:99018"/>
          <criterion comment="kvm-tools is earlier than 0:83-105.el5_4.27" test_ref="oval:org.mitre.oval:tst:99200"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22113" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1458: bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1458-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1458.html"/>
        <reference source="CESA" ref_id="CESA-2011:1458"/>
        <reference source="CVE" ref_id="CVE-2011-4313" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4313.html"/>
        <description>query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named exit) via unknown vectors related to recursive DNS queries, error logging, and the caching of an invalid record by the resolver.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:16.451-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:21.410-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:44.035-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bind is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98079"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98197"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98439"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98132"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98609"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98408"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98665"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98532"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bind is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:98698"/>
            <criterion comment="bind-chroot is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:98367"/>
            <criterion comment="bind-sdb is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:98426"/>
            <criterion comment="bind-libs is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:98202"/>
            <criterion comment="bind-devel is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:98553"/>
            <criterion comment="bind-utils is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:98690"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22110" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0291: gfs-kmod security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>gfs-kmod</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0291-04" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0291.html"/>
        <reference source="CVE" ref_id="CVE-2010-0727" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0727.html"/>
        <description>The gfs2_lock function in the Linux kernel before 2.6.34-rc1-next-20100312, and the gfs_lock function in the Linux kernel on Red Hat Enterprise Linux (RHEL) 5 and 6, does not properly remove POSIX locks on files that are setgid without group-execute permission, which allows local users to cause a denial of service (BUG and system crash) by locking a file on a (1) GFS or (2) GFS2 filesystem, and then changing this file's permissions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:11.205-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:21.322-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:43.932-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kmod-gfs is earlier than 0:0.1.34-12.el5" test_ref="oval:org.mitre.oval:tst:99228"/>
          <criterion comment="kmod-gfs-PAE is earlier than 0:0.1.34-12.el5" test_ref="oval:org.mitre.oval:tst:98347"/>
          <criterion comment="kmod-gfs-xen is earlier than 0:0.1.34-12.el5" test_ref="oval:org.mitre.oval:tst:98693"/>
          <criterion comment="gfs-kmod is earlier than 0:0.1.34-12.el5" test_ref="oval:org.mitre.oval:tst:99139"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22109" version="5" class="patch">
      <metadata>
        <title>RHSA-2011:1242: firefox security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1242-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1242.html"/>
        <reference source="CESA" ref_id="CESA-2011:1242"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

It was found that a Certificate Authority (CA) issued a fraudulent HTTPS
certificate. This update renders any HTTPS certificates signed by that
CA as untrusted, except for a select few. The now untrusted certificates
that were issued before July 1, 2011 can be manually re-enabled and used
again at your own risk in Firefox; however, affected certificates issued
after this date cannot be re-enabled or used. (BZ#734316)

All Firefox users should upgrade to these updated packages, which contain
a backported patch. After installing the update, Firefox must be restarted
for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:19.848-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:21.256-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:43.845-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22109 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:38.859-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:46.417-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.20-3.el5_7" test_ref="oval:org.mitre.oval:tst:98420"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.20-3.el5_7" test_ref="oval:org.mitre.oval:tst:97841"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.20-3.el6_1" test_ref="oval:org.mitre.oval:tst:98240"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.20-3.el6_1" test_ref="oval:org.mitre.oval:tst:98391"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22107" version="55" class="patch">
      <metadata>
        <title>RHSA-2010:0580: tomcat5 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>tomcat5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0580-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0580.html"/>
        <reference source="CESA" ref_id="CESA-2010:0580"/>
        <reference source="CVE" ref_id="CVE-2009-2693" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2693.html"/>
        <reference source="CVE" ref_id="CVE-2009-2696" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2696.html"/>
        <reference source="CVE" ref_id="CVE-2009-2902" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2902.html"/>
        <reference source="CVE" ref_id="CVE-2010-2227" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2227.html"/>
        <description>Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:35.791-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:20.992-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:43.466-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:98790"/>
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:99170"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:98699"/>
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:99591"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:99259"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:99137"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:99283"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:99329"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:99357"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:99375"/>
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:99587"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22101" version="328" class="patch">
      <metadata>
        <title>RHSA-2010:0338: java-1.5.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0338-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0338.html"/>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html"/>
        <reference source="CVE" ref_id="CVE-2010-0082" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0082.html"/>
        <reference source="CVE" ref_id="CVE-2010-0084" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0084.html"/>
        <reference source="CVE" ref_id="CVE-2010-0085" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0085.html"/>
        <reference source="CVE" ref_id="CVE-2010-0087" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0087.html"/>
        <reference source="CVE" ref_id="CVE-2010-0088" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0088.html"/>
        <reference source="CVE" ref_id="CVE-2010-0089" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0089.html"/>
        <reference source="CVE" ref_id="CVE-2010-0091" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0091.html"/>
        <reference source="CVE" ref_id="CVE-2010-0092" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0092.html"/>
        <reference source="CVE" ref_id="CVE-2010-0093" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0093.html"/>
        <reference source="CVE" ref_id="CVE-2010-0094" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0094.html"/>
        <reference source="CVE" ref_id="CVE-2010-0095" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0095.html"/>
        <reference source="CVE" ref_id="CVE-2010-0837" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0837.html"/>
        <reference source="CVE" ref_id="CVE-2010-0838" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0838.html"/>
        <reference source="CVE" ref_id="CVE-2010-0839" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0839.html"/>
        <reference source="CVE" ref_id="CVE-2010-0840" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0840.html"/>
        <reference source="CVE" ref_id="CVE-2010-0841" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0841.html"/>
        <reference source="CVE" ref_id="CVE-2010-0842" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0842.html"/>
        <reference source="CVE" ref_id="CVE-2010-0843" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0843.html"/>
        <reference source="CVE" ref_id="CVE-2010-0844" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0844.html"/>
        <reference source="CVE" ref_id="CVE-2010-0845" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0845.html"/>
        <reference source="CVE" ref_id="CVE-2010-0846" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0846.html"/>
        <reference source="CVE" ref_id="CVE-2010-0847" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0847.html"/>
        <reference source="CVE" ref_id="CVE-2010-0848" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0848.html"/>
        <reference source="CVE" ref_id="CVE-2010-0849" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0849.html"/>
        <description>Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow in a decoding routine used by the JPEGImageDecoderImpl interface, which allows code execution via a crafted JPEG image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:18.113-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:19.639-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:42.145-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.5.0-sun-uninstall is earlier than 0:1.5.0.22-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:99214"/>
          <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.22-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:99073"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22098" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0488: samba and samba3x security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>samba</product>
          <product>samba3x</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0488-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0488.html"/>
        <reference source="CESA" ref_id="CESA-2010:0488"/>
        <reference source="CVE" ref_id="CVE-2010-2063" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2063.html"/>
        <description>Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted field in a packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:14.592-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:19.514-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:42.028-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libsmbclient is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:99333"/>
          <criterion comment="samba-client is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:99449"/>
          <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:99368"/>
          <criterion comment="samba-common is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:98893"/>
          <criterion comment="samba is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:99396"/>
          <criterion comment="samba-swat is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:99110"/>
          <criterion comment="tdb-tools is earlier than 0:1.1.2-52.el5_5" test_ref="oval:org.mitre.oval:tst:98816"/>
          <criterion comment="samba3x-swat is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:99388"/>
          <criterion comment="libtdb is earlier than 0:1.1.2-52.el5_5" test_ref="oval:org.mitre.oval:tst:99164"/>
          <criterion comment="samba3x-client is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:99448"/>
          <criterion comment="samba3x-doc is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:98572"/>
          <criterion comment="libtalloc-devel is earlier than 0:1.2.0-52.el5_5" test_ref="oval:org.mitre.oval:tst:99537"/>
          <criterion comment="samba3x-winbind is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:99427"/>
          <criterion comment="samba3x is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:99192"/>
          <criterion comment="samba3x-winbind-devel is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:99309"/>
          <criterion comment="libtalloc is earlier than 0:1.2.0-52.el5_5" test_ref="oval:org.mitre.oval:tst:98689"/>
          <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:98992"/>
          <criterion comment="libtdb-devel is earlier than 0:1.1.2-52.el5_5" test_ref="oval:org.mitre.oval:tst:99197"/>
          <criterion comment="samba3x-common is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:98555"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22095" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1132: dbus security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>dbus</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1132-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1132.html"/>
        <reference source="CESA" ref_id="CESA-2011:1132"/>
        <reference source="CVE" ref_id="CVE-2011-2200" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2200.html"/>
        <description>The _dbus_header_byteswap function in dbus-marshal-header.c in D-Bus (aka DBus) 1.2.x before 1.2.28, 1.4.x before 1.4.12, and 1.5.x before 1.5.4 does not properly handle a non-native byte order, which allows local users to cause a denial of service (connection loss), obtain potentially sensitive information, or conduct unspecified state-modification attacks via crafted messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:14.978-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:19.349-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:41.858-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dbus-devel is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:98328"/>
            <criterion comment="dbus is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:98336"/>
            <criterion comment="dbus-x11 is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:98184"/>
            <criterion comment="dbus-libs is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:98270"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dbus-devel is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:98037"/>
            <criterion comment="dbus is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:98321"/>
            <criterion comment="dbus-x11 is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:98046"/>
            <criterion comment="dbus-libs is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:98018"/>
            <criterion comment="dbus-doc is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:97803"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22092" version="87" class="patch">
      <metadata>
        <title>RHSA-2014:0136: java-1.5.0-ibm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0136-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0136.html"/>
        <reference source="CVE" ref_id="CVE-2013-5907" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5907.html"/>
        <reference source="CVE" ref_id="CVE-2014-0368" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0368.html"/>
        <reference source="CVE" ref_id="CVE-2014-0373" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0373.html"/>
        <reference source="CVE" ref_id="CVE-2014-0376" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0376.html"/>
        <reference source="CVE" ref_id="CVE-2014-0411" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0411.html"/>
        <reference source="CVE" ref_id="CVE-2014-0416" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0416.html"/>
        <reference source="CVE" ref_id="CVE-2014-0417" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0417.html"/>
        <reference source="CVE" ref_id="CVE-2014-0422" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0422.html"/>
        <reference source="CVE" ref_id="CVE-2014-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0423.html"/>
        <reference source="CVE" ref_id="CVE-2014-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0428.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:21.283-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:37.818-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:15.848-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22092 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:18.268-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:11.292-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22092 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:40.947-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:29.515-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:140911"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:140690"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141017"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141058"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141222"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141185"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141143"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:140793"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100347"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100452"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100222"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100379"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100372"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100369"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:99973"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22091" version="94" class="patch">
      <metadata>
        <title>RHSA-2010:0610: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0610-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0610.html"/>
        <reference source="CESA" ref_id="CESA-2010:0610"/>
        <reference source="CVE" ref_id="CVE-2010-1084" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1084.html"/>
        <reference source="CVE" ref_id="CVE-2010-2066" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2066.html"/>
        <reference source="CVE" ref_id="CVE-2010-2070" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2070.html"/>
        <reference source="CVE" ref_id="CVE-2010-2226" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2226.html"/>
        <reference source="CVE" ref_id="CVE-2010-2248" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2248.html"/>
        <reference source="CVE" ref_id="CVE-2010-2521" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2521.html"/>
        <reference source="CVE" ref_id="CVE-2010-2524" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2524.html"/>
        <description>The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the cifs.upcall userspace helper, which allows local users to spoof the results of DNS queries and perform arbitrary CIFS mounts via vectors involving an add_key call, related to a "cache stuffing" issue and MS-DFS referrals.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:41.133-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:18.932-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:41.440-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:99615"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:99182"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:99655"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:99412"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:99631"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:99262"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:99347"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:99679"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:99350"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:99271"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:99497"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:99474"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22090" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0003: gd security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0003-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0003.html"/>
        <reference source="CESA" ref_id="CESA-2010:0003"/>
        <reference source="CVE" ref_id="CVE-2009-3546" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3546.html"/>
        <description>The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:10.752-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:18.819-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:41.333-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="gd-devel is earlier than 0:2.0.33-9.4.el5_4.2" test_ref="oval:org.mitre.oval:tst:98918"/>
          <criterion comment="gd-progs is earlier than 0:2.0.33-9.4.el5_4.2" test_ref="oval:org.mitre.oval:tst:98778"/>
          <criterion comment="gd is earlier than 0:2.0.33-9.4.el5_4.2" test_ref="oval:org.mitre.oval:tst:98922"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22088" version="341" class="patch">
      <metadata>
        <title>RHSA-2010:0337: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0337-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0337.html"/>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html"/>
        <reference source="CVE" ref_id="CVE-2010-0082" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0082.html"/>
        <reference source="CVE" ref_id="CVE-2010-0084" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0084.html"/>
        <reference source="CVE" ref_id="CVE-2010-0085" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0085.html"/>
        <reference source="CVE" ref_id="CVE-2010-0087" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0087.html"/>
        <reference source="CVE" ref_id="CVE-2010-0088" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0088.html"/>
        <reference source="CVE" ref_id="CVE-2010-0089" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0089.html"/>
        <reference source="CVE" ref_id="CVE-2010-0090" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0090.html"/>
        <reference source="CVE" ref_id="CVE-2010-0091" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0091.html"/>
        <reference source="CVE" ref_id="CVE-2010-0092" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0092.html"/>
        <reference source="CVE" ref_id="CVE-2010-0093" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0093.html"/>
        <reference source="CVE" ref_id="CVE-2010-0094" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0094.html"/>
        <reference source="CVE" ref_id="CVE-2010-0095" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0095.html"/>
        <reference source="CVE" ref_id="CVE-2010-0837" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0837.html"/>
        <reference source="CVE" ref_id="CVE-2010-0838" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0838.html"/>
        <reference source="CVE" ref_id="CVE-2010-0839" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0839.html"/>
        <reference source="CVE" ref_id="CVE-2010-0840" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0840.html"/>
        <reference source="CVE" ref_id="CVE-2010-0841" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0841.html"/>
        <reference source="CVE" ref_id="CVE-2010-0842" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0842.html"/>
        <reference source="CVE" ref_id="CVE-2010-0843" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0843.html"/>
        <reference source="CVE" ref_id="CVE-2010-0844" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0844.html"/>
        <reference source="CVE" ref_id="CVE-2010-0845" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0845.html"/>
        <reference source="CVE" ref_id="CVE-2010-0846" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0846.html"/>
        <reference source="CVE" ref_id="CVE-2010-0847" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0847.html"/>
        <reference source="CVE" ref_id="CVE-2010-0848" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0848.html"/>
        <reference source="CVE" ref_id="CVE-2010-0849" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0849.html"/>
        <description>Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow in a decoding routine used by the JPEGImageDecoderImpl interface, which allows code execution via a crafted JPEG image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:50.266-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:18.143-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:40.558-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.19-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98936"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.19-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99257"/>
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.19-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99325"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.19-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98807"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.19-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99089"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.19-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99099"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22081" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0108: NetworkManager security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>NetworkManager</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0108-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0108.html"/>
        <reference source="CESA" ref_id="CESA-2010:0108"/>
        <reference source="CVE" ref_id="CVE-2009-4144" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4144.html"/>
        <reference source="CVE" ref_id="CVE-2009-4145" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4145.html"/>
        <description>nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading D-Bus signals, as demonstrated by using dbus-monitor to discover the password for the WiFi network.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:43.391-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:17.904-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:40.176-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="NetworkManager-glib is earlier than 1:0.7.0-9.el5_4" test_ref="oval:org.mitre.oval:tst:99252"/>
          <criterion comment="NetworkManager-devel is earlier than 1:0.7.0-9.el5_4" test_ref="oval:org.mitre.oval:tst:98732"/>
          <criterion comment="NetworkManager-gnome is earlier than 1:0.7.0-9.el5_4" test_ref="oval:org.mitre.oval:tst:99145"/>
          <criterion comment="NetworkManager-glib-devel is earlier than 1:0.7.0-9.el5_4" test_ref="oval:org.mitre.oval:tst:98972"/>
          <criterion comment="NetworkManager is earlier than 1:0.7.0-9.el5_4" test_ref="oval:org.mitre.oval:tst:98932"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22080" version="42" class="patch">
      <metadata>
        <title>RHSA-2010:0720: mikmod security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>mikmod</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0720-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0720.html"/>
        <reference source="CESA" ref_id="CESA-2010:0720"/>
        <reference source="CVE" ref_id="CVE-2007-6720" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6720.html"/>
        <reference source="CVE" ref_id="CVE-2009-3995" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3995.html"/>
        <reference source="CVE" ref_id="CVE-2009-3996" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3996.html"/>
        <description>Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote attackers to execute arbitrary code via an Ultratracker file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:26.848-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:17.775-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:40.043-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mikmod is earlier than 0:3.1.6-39.el5_5.1" test_ref="oval:org.mitre.oval:tst:99559"/>
          <criterion comment="mikmod-devel is earlier than 0:3.1.6-39.el5_5.1" test_ref="oval:org.mitre.oval:tst:99594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22076" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0661: kernel security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0661-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0661.html"/>
        <reference source="CESA" ref_id="CESA-2010:0661"/>
        <reference source="CVE" ref_id="CVE-2010-2240" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2240.html"/>
        <description>The do_anonymous_page function in mm/memory.c in the Linux kernel before 2.6.27.52, 2.6.32.x before 2.6.32.19, 2.6.34.x before 2.6.34.4, and 2.6.35.x before 2.6.35.2 does not properly separate the stack and the heap, which allows context-dependent attackers to execute arbitrary code by writing to the bottom page of a shared memory segment, as demonstrated by a memory-exhaustion attack against the X.Org X server.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:07.564-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:17.481-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:39.694-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:99601"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:98785"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:99726"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:99354"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:99519"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:99020"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:99556"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:99641"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:99575"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:98947"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:98731"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:99208"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22075" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1508: cyrus-imapd security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>cyrus-imapd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1508-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1508.html"/>
        <reference source="CESA" ref_id="CESA-2011:1508"/>
        <reference source="CVE" ref_id="CVE-2011-3372" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3372.html"/>
        <reference source="CVE" ref_id="CVE-2011-3481" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3481.html"/>
        <description>The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted References header in an e-mail message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:21.703-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:17.360-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:39.523-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.7-12.el5_7.2" test_ref="oval:org.mitre.oval:tst:98879"/>
            <criterion comment="cyrus-imapd-perl is earlier than 0:2.3.7-12.el5_7.2" test_ref="oval:org.mitre.oval:tst:98824"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.7-12.el5_7.2" test_ref="oval:org.mitre.oval:tst:98303"/>
            <criterion comment="cyrus-imapd is earlier than 0:2.3.7-12.el5_7.2" test_ref="oval:org.mitre.oval:tst:98664"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.4" test_ref="oval:org.mitre.oval:tst:98492"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.4" test_ref="oval:org.mitre.oval:tst:98649"/>
            <criterion comment="cyrus-imapd is earlier than 0:2.3.16-6.el6_1.4" test_ref="oval:org.mitre.oval:tst:98654"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22074" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0585: lftp security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>lftp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0585-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0585.html"/>
        <reference source="CESA" ref_id="CESA-2010:0585"/>
        <reference source="CVE" ref_id="CVE-2010-2251" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2251.html"/>
        <description>The get1 command, as used by lftpget, in LFTP before 4.0.6 does not properly validate a server-provided filename before determining the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:43.103-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:17.275-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:39.425-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="lftp is earlier than 0:3.7.11-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:99586"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22071" version="5" class="patch">
      <metadata>
        <title>RHSA-2011:1243: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1243-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1243.html"/>
        <reference source="CESA" ref_id="CESA-2011:1243"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

It was found that a Certificate Authority (CA) issued a fraudulent HTTPS
certificate. This update renders any HTTPS certificates signed by that
CA as untrusted, except for a select few. The now untrusted certificates
that were issued before July 1, 2011 can be manually re-enabled and used
again at your own risk in Thunderbird; however, affected certificates
issued after this date cannot be re-enabled or used. (BZ#734316)

All Thunderbird users should upgrade to this updated package, which
resolves this issue. All running instances of Thunderbird must be
restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:17.510-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:16.987-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:39.160-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22071 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:40.846-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:45.918-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:2.0.0.24-24.el5" test_ref="oval:org.mitre.oval:tst:98185"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="thunderbird is earlier than 0:3.1.12-2.el6_1" test_ref="oval:org.mitre.oval:tst:98102"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22063" version="198" class="patch">
      <metadata>
        <title>RHSA-2010:0349: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0349-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0349.html"/>
        <reference source="CVE" ref_id="CVE-2010-0190" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0190.html"/>
        <reference source="CVE" ref_id="CVE-2010-0191" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0191.html"/>
        <reference source="CVE" ref_id="CVE-2010-0192" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0192.html"/>
        <reference source="CVE" ref_id="CVE-2010-0193" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0193.html"/>
        <reference source="CVE" ref_id="CVE-2010-0194" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0194.html"/>
        <reference source="CVE" ref_id="CVE-2010-0195" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0195.html"/>
        <reference source="CVE" ref_id="CVE-2010-0196" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0196.html"/>
        <reference source="CVE" ref_id="CVE-2010-0197" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0197.html"/>
        <reference source="CVE" ref_id="CVE-2010-0198" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0198.html"/>
        <reference source="CVE" ref_id="CVE-2010-0199" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0199.html"/>
        <reference source="CVE" ref_id="CVE-2010-0201" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0201.html"/>
        <reference source="CVE" ref_id="CVE-2010-0202" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0202.html"/>
        <reference source="CVE" ref_id="CVE-2010-0203" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0203.html"/>
        <reference source="CVE" ref_id="CVE-2010-0204" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0204.html"/>
        <reference source="CVE" ref_id="CVE-2010-1241" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1241.html"/>
        <description>Heap-based buffer overflow in the custom heap management system in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, aka FG-VD-10-005.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:36.064-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:16.189-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:38.389-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="acroread-plugin is earlier than 0:9.3.2-1.el5" test_ref="oval:org.mitre.oval:tst:99130"/>
          <criterion comment="acroread is earlier than 0:9.3.2-1.el5" test_ref="oval:org.mitre.oval:tst:98447"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22062" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1154: libXfont security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libXfont</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1154-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1154.html"/>
        <reference source="CESA" ref_id="CESA-2011:1154"/>
        <reference source="CVE" ref_id="CVE-2011-2895" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2895.html"/>
        <description>The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows context-dependent attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2896.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:58.917-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:16.083-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:38.288-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libXfont is earlier than 0:1.2.2-1.0.4.el5_7" test_ref="oval:org.mitre.oval:tst:98313"/>
            <criterion comment="libXfont-devel is earlier than 0:1.2.2-1.0.4.el5_7" test_ref="oval:org.mitre.oval:tst:97879"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libXfont is earlier than 0:1.4.1-2.el6_1" test_ref="oval:org.mitre.oval:tst:98314"/>
            <criterion comment="libXfont-devel is earlier than 0:1.4.1-2.el6_1" test_ref="oval:org.mitre.oval:tst:98105"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22059" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0970: exim security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>exim</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0970-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0970.html"/>
        <reference source="CVE" ref_id="CVE-2010-4344" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4344.html"/>
        <description>Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:25.217-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:15.885-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:38.029-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="exim-mon is earlier than 0:4.63-5.el5_5.2" test_ref="oval:org.mitre.oval:tst:99990"/>
          <criterion comment="exim is earlier than 0:4.63-5.el5_5.2" test_ref="oval:org.mitre.oval:tst:99492"/>
          <criterion comment="exim-sa is earlier than 0:4.63-5.el5_5.2" test_ref="oval:org.mitre.oval:tst:99910"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22058" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0237: sendmail security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>sendmail</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0237-05" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0237.html"/>
        <reference source="CVE" ref_id="CVE-2006-7176" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7176.html"/>
        <reference source="CVE" ref_id="CVE-2009-4565" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4565.html"/>
        <description>sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:23.387-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:15.776-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:37.901-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="sendmail is earlier than 0:8.13.8-8.el5" test_ref="oval:org.mitre.oval:tst:98900"/>
          <criterion comment="sendmail-doc is earlier than 0:8.13.8-8.el5" test_ref="oval:org.mitre.oval:tst:99031"/>
          <criterion comment="sendmail-devel is earlier than 0:8.13.8-8.el5" test_ref="oval:org.mitre.oval:tst:99035"/>
          <criterion comment="sendmail-cf is earlier than 0:8.13.8-8.el5" test_ref="oval:org.mitre.oval:tst:98980"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22053" version="393" class="patch">
      <metadata>
        <title>RHSA-2010:0464: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0464-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0464.html"/>
        <reference source="CVE" ref_id="CVE-2008-4546" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4546.html"/>
        <reference source="CVE" ref_id="CVE-2009-3793" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3793.html"/>
        <reference source="CVE" ref_id="CVE-2010-1297" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1297.html"/>
        <reference source="CVE" ref_id="CVE-2010-2160" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2160.html"/>
        <reference source="CVE" ref_id="CVE-2010-2161" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2161.html"/>
        <reference source="CVE" ref_id="CVE-2010-2162" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2162.html"/>
        <reference source="CVE" ref_id="CVE-2010-2163" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2163.html"/>
        <reference source="CVE" ref_id="CVE-2010-2164" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2164.html"/>
        <reference source="CVE" ref_id="CVE-2010-2165" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2165.html"/>
        <reference source="CVE" ref_id="CVE-2010-2166" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2166.html"/>
        <reference source="CVE" ref_id="CVE-2010-2167" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2167.html"/>
        <reference source="CVE" ref_id="CVE-2010-2169" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2169.html"/>
        <reference source="CVE" ref_id="CVE-2010-2170" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2170.html"/>
        <reference source="CVE" ref_id="CVE-2010-2171" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2171.html"/>
        <reference source="CVE" ref_id="CVE-2010-2173" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2173.html"/>
        <reference source="CVE" ref_id="CVE-2010-2174" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2174.html"/>
        <reference source="CVE" ref_id="CVE-2010-2175" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2175.html"/>
        <reference source="CVE" ref_id="CVE-2010-2176" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2176.html"/>
        <reference source="CVE" ref_id="CVE-2010-2177" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2177.html"/>
        <reference source="CVE" ref_id="CVE-2010-2178" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2178.html"/>
        <reference source="CVE" ref_id="CVE-2010-2179" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2179.html"/>
        <reference source="CVE" ref_id="CVE-2010-2180" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2180.html"/>
        <reference source="CVE" ref_id="CVE-2010-2181" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2181.html"/>
        <reference source="CVE" ref_id="CVE-2010-2182" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2182.html"/>
        <reference source="CVE" ref_id="CVE-2010-2183" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2183.html"/>
        <reference source="CVE" ref_id="CVE-2010-2184" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2184.html"/>
        <reference source="CVE" ref_id="CVE-2010-2185" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2185.html"/>
        <reference source="CVE" ref_id="CVE-2010-2186" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2186.html"/>
        <reference source="CVE" ref_id="CVE-2010-2187" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2187.html"/>
        <reference source="CVE" ref_id="CVE-2010-2188" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2188.html"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code by calling the ActionScript native object 2200 connect method multiple times with different arguments, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, and CVE-2010-2187.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:04.909-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:14.462-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:36.312-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="flash-plugin is earlier than 0:10.1-2.el5" test_ref="oval:org.mitre.oval:tst:99324"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22050" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0894: systemtap security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>systemtap</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0894-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0894.html"/>
        <reference source="CESA" ref_id="CESA-2010:0894"/>
        <reference source="CVE" ref_id="CVE-2010-4170" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4170.html"/>
        <reference source="CVE" ref_id="CVE-2010-4171" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4171.html"/>
        <description>The staprun runtime tool in SystemTap 1.3 does not verify that a module to unload was previously loaded by SystemTap, which allows local users to cause a denial of service (unloading of arbitrary kernel modules).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:28.024-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:13.991-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:36.064-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="systemtap-client is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:99854"/>
            <criterion comment="systemtap-runtime is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:99981"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:99942"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:100006"/>
            <criterion comment="systemtap is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:99833"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:99969"/>
            <criterion comment="systemtap-server is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:99936"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="systemtap-runtime is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:99849"/>
            <criterion comment="systemtap-client is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:99847"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:99852"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:99935"/>
            <criterion comment="systemtap is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:99429"/>
            <criterion comment="systemtap-grapher is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:99529"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:99939"/>
            <criterion comment="systemtap-server is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:99908"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22049" version="187" class="patch">
      <metadata>
        <title>RHSA-2014:0027: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0027-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0027.html"/>
        <reference source="CESA" ref_id="CESA-2014:0027"/>
        <reference source="CVE" ref_id="CVE-2013-5878" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5878.html"/>
        <reference source="CVE" ref_id="CVE-2013-5884" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5884.html"/>
        <reference source="CVE" ref_id="CVE-2013-5893" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5893.html"/>
        <reference source="CVE" ref_id="CVE-2013-5896" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5896.html"/>
        <reference source="CVE" ref_id="CVE-2013-5907" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5907.html"/>
        <reference source="CVE" ref_id="CVE-2013-5910" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5910.html"/>
        <reference source="CVE" ref_id="CVE-2014-0368" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0368.html"/>
        <reference source="CVE" ref_id="CVE-2014-0373" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0373.html"/>
        <reference source="CVE" ref_id="CVE-2014-0376" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0376.html"/>
        <reference source="CVE" ref_id="CVE-2014-0411" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0411.html"/>
        <reference source="CVE" ref_id="CVE-2014-0416" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0416.html"/>
        <reference source="CVE" ref_id="CVE-2014-0422" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0422.html"/>
        <reference source="CVE" ref_id="CVE-2014-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0423.html"/>
        <reference source="CVE" ref_id="CVE-2014-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0428.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:58:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:42:30.560-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:13.693-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:35.509-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22049 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:40.523-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:42.404-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.51-2.4.4.1.el5_10" test_ref="oval:org.mitre.oval:tst:98727"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.51-2.4.4.1.el5_10" test_ref="oval:org.mitre.oval:tst:98933"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.51-2.4.4.1.el5_10" test_ref="oval:org.mitre.oval:tst:98910"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.51-2.4.4.1.el5_10" test_ref="oval:org.mitre.oval:tst:98833"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.51-2.4.4.1.el5_10" test_ref="oval:org.mitre.oval:tst:98086"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22045" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0633: qspice security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>qspice</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0633-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0633.html"/>
        <reference source="CESA" ref_id="CESA-2010:0633"/>
        <reference source="CVE" ref_id="CVE-2010-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0428.html"/>
        <reference source="CVE" ref_id="CVE-2010-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0429.html"/>
        <description>libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not properly restrict the addresses upon which memory-management actions are performed, which allows guest OS users to cause a denial of service (guest OS crash) or possibly gain privileges via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:58.862-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:13.605-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:35.384-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="qspice is earlier than 0:0.3.0-54.el5_5.2" test_ref="oval:org.mitre.oval:tst:99685"/>
          <criterion comment="qspice-libs is earlier than 0:0.3.0-54.el5_5.2" test_ref="oval:org.mitre.oval:tst:98917"/>
          <criterion comment="qspice-libs-devel is earlier than 0:0.3.0-54.el5_5.2" test_ref="oval:org.mitre.oval:tst:99629"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22042" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0703: bzip2 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bzip2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0703-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0703.html"/>
        <reference source="CESA" ref_id="CESA-2010:0703"/>
        <reference source="CVE" ref_id="CVE-2010-0405" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0405.html"/>
        <description>Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:02.946-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:13.535-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:35.283-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="bzip2-devel is earlier than 0:1.0.3-6.el5_5" test_ref="oval:org.mitre.oval:tst:99414"/>
          <criterion comment="bzip2-libs is earlier than 0:1.0.3-6.el5_5" test_ref="oval:org.mitre.oval:tst:99075"/>
          <criterion comment="bzip2 is earlier than 0:1.0.3-6.el5_5" test_ref="oval:org.mitre.oval:tst:98748"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22040" version="5" class="patch">
      <metadata>
        <title>RHSA-2011:1282: nss and nspr security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>nspr</product>
          <product>nss</product>
          <product>nss-tools</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1282-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1282.html"/>
        <reference source="CESA" ref_id="CESA-2011:1282"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications.

Netscape Portable Runtime (NSPR) provides platform independence for non-GUI
operating system facilities.

It was found that a Certificate Authority (CA) issued fraudulent HTTPS
certificates. This update renders any HTTPS certificates signed by that CA
as untrusted. This covers all uses of the certificates, including SSL,
S/MIME, and code signing. (BZ#734316)

Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.

These updated packages upgrade NSS to version 3.12.10 on Red Hat Enterprise
Linux 4 and 5. As well, they upgrade NSPR to version 4.8.8 on Red Hat
Enterprise Linux 4 and 5, as required by the NSS update. The packages for
Red Hat Enterprise Linux 6 include a backported patch.

All NSS and NSPR users should upgrade to these updated packages, which
correct this issue. After installing the update, applications using NSS and
NSPR must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:22.516-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:13.466-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:35.154-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22040 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:41.766-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:42.231-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="nspr is earlier than 0:4.8.8-1.el5_7" test_ref="oval:org.mitre.oval:tst:98459"/>
            <criterion comment="nspr-devel is earlier than 0:4.8.8-1.el5_7" test_ref="oval:org.mitre.oval:tst:98043"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:98470"/>
            <criterion comment="nss-tools is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:98343"/>
            <criterion comment="nss is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:98293"/>
            <criterion comment="nss-devel is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:98362"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:98140"/>
            <criterion comment="nss-tools is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:98271"/>
            <criterion comment="nss-sysinit is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:98482"/>
            <criterion comment="nss is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:98530"/>
            <criterion comment="nss-devel is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:98382"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22039" version="81" class="patch">
      <metadata>
        <title>RHSA-2011:1333: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1333-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1333.html"/>
        <reference source="CVE" ref_id="CVE-2011-2426" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2426.html"/>
        <reference source="CVE" ref_id="CVE-2011-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2427.html"/>
        <reference source="CVE" ref_id="CVE-2011-2428" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2428.html"/>
        <reference source="CVE" ref_id="CVE-2011-2429" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2429.html"/>
        <reference source="CVE" ref_id="CVE-2011-2430" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2430.html"/>
        <reference source="CVE" ref_id="CVE-2011-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2444.html"/>
        <description>Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to a "universal cross-site scripting issue," as exploited in the wild in September 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:14.771-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:13.289-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:34.912-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.10-1.el5" test_ref="oval:org.mitre.oval:tst:98478"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.10-1.el6" test_ref="oval:org.mitre.oval:tst:98466"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22038" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0978: openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0978-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0978.html"/>
        <reference source="CESA" ref_id="CESA-2010:0978"/>
        <reference source="CVE" ref_id="CVE-2008-7270" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-7270.html"/>
        <reference source="CVE" ref_id="CVE-2010-4180" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4180.html"/>
        <description>OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:54.529-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:13.197-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:34.781-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openssl is earlier than 0:0.9.8e-12.el5_5.7" test_ref="oval:org.mitre.oval:tst:99761"/>
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-12.el5_5.7" test_ref="oval:org.mitre.oval:tst:99762"/>
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-12.el5_5.7" test_ref="oval:org.mitre.oval:tst:99708"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22037" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0343: krb5 security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0343-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0343.html"/>
        <reference source="CESA" ref_id="CESA-2010:0343"/>
        <reference source="CVE" ref_id="CVE-2010-0629" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0629.html"/>
        <description>Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a kadmin client that sends an invalid API version number.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:31.068-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:13.125-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:34.672-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="krb5-libs is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:99301"/>
          <criterion comment="krb5-devel is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:98380"/>
          <criterion comment="krb5-server is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:99178"/>
          <criterion comment="krb5 is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:99146"/>
          <criterion comment="krb5-workstation is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:98815"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22035" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0271: kvm security, bug fix and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0271-05" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0271.html"/>
        <reference source="CVE" ref_id="CVE-2010-0430" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0430.html"/>
        <reference source="CVE" ref_id="CVE-2010-0741" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0741.html"/>
        <description>The virtio_net_bad_features function in hw/virtio-net.c in the virtio-net driver in the Linux kernel before 2.6.26, when used on a guest OS in conjunction with qemu-kvm 0.11.0 or KVM 83, allows remote attackers to cause a denial of service (guest OS crash, and an associated qemu-kvm process exit) by sending a large amount of network traffic to a TCP port on the guest OS, related to a virtio-net whitelist that includes an improper implementation of TCP Segment Offloading (TSO).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:23.110-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:13.045-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:34.546-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kvm-qemu-img is earlier than 0:83-164.el5" test_ref="oval:org.mitre.oval:tst:99086"/>
          <criterion comment="kvm is earlier than 0:83-164.el5" test_ref="oval:org.mitre.oval:tst:99187"/>
          <criterion comment="kmod-kvm is earlier than 0:83-164.el5" test_ref="oval:org.mitre.oval:tst:99238"/>
          <criterion comment="kvm-tools is earlier than 0:83-164.el5" test_ref="oval:org.mitre.oval:tst:99258"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22033" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1005: sysstat security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>sysstat</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1005-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1005.html"/>
        <reference source="CESA" ref_id="CESA-2011:1005"/>
        <reference source="CVE" ref_id="CVE-2007-3852" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3852.html"/>
        <description>The init script (sysstat.in) in sysstat 5.1.2 up to 7.1.6 creates /tmp/sysstat.run insecurely, which allows local users to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:54.979-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:12.976-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:34.440-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="sysstat is earlier than 0:7.0.2-11.el5" test_ref="oval:org.mitre.oval:tst:98161"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22030" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0129: cups security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0129-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0129.html"/>
        <reference source="CESA" ref_id="CESA-2010:0129"/>
        <reference source="CVE" ref_id="CVE-2010-0302" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0302.html"/>
        <description>Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3553.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:29.354-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:12.905-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:34.341-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="cups-lpd is earlier than 1:1.3.7-11.el5_4.6" test_ref="oval:org.mitre.oval:tst:98829"/>
          <criterion comment="cups-devel is earlier than 1:1.3.7-11.el5_4.6" test_ref="oval:org.mitre.oval:tst:99195"/>
          <criterion comment="cups-libs is earlier than 1:1.3.7-11.el5_4.6" test_ref="oval:org.mitre.oval:tst:99148"/>
          <criterion comment="cups is earlier than 1:1.3.7-11.el5_4.6" test_ref="oval:org.mitre.oval:tst:99033"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22026" version="172" class="patch">
      <metadata>
        <title>RHSA-2011:0887: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0887-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0887.html"/>
        <reference source="CESA" ref_id="CESA-2011:0887"/>
        <reference source="CVE" ref_id="CVE-2011-0083" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0083.html"/>
        <reference source="CVE" ref_id="CVE-2011-0085" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0085.html"/>
        <reference source="CVE" ref_id="CVE-2011-2362" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2362.html"/>
        <reference source="CVE" ref_id="CVE-2011-2363" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2363.html"/>
        <reference source="CVE" ref_id="CVE-2011-2364" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2364.html"/>
        <reference source="CVE" ref_id="CVE-2011-2365" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2365.html"/>
        <reference source="CVE" ref_id="CVE-2011-2371" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2371.html"/>
        <reference source="CVE" ref_id="CVE-2011-2373" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2373.html"/>
        <reference source="CVE" ref_id="CVE-2011-2374" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2374.html"/>
        <reference source="CVE" ref_id="CVE-2011-2375" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2375.html"/>
        <reference source="CVE" ref_id="CVE-2011-2376" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2376.html"/>
        <reference source="CVE" ref_id="CVE-2011-2377" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2377.html"/>
        <reference source="CVE" ref_id="CVE-2011-2605" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2605.html"/>
        <description>CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/cookie/nsCookieService.cpp in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allows remote attackers to bypass intended access restrictions via a string containing a \n (newline) character, which is not properly handled in a JavaScript "document.cookie =" expression, a different vulnerability than CVE-2011-2374.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:14.173-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:12.623-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:33.860-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-18.el5_6" test_ref="oval:org.mitre.oval:tst:98045"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22022" version="94" class="patch">
      <metadata>
        <title>RHSA-2010:0919: php security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0919-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0919.html"/>
        <reference source="CESA" ref_id="CESA-2010:0919"/>
        <reference source="CVE" ref_id="CVE-2009-5016" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-5016.html"/>
        <reference source="CVE" ref_id="CVE-2010-0397" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0397.html"/>
        <reference source="CVE" ref_id="CVE-2010-1128" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1128.html"/>
        <reference source="CVE" ref_id="CVE-2010-1917" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1917.html"/>
        <reference source="CVE" ref_id="CVE-2010-2531" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2531.html"/>
        <reference source="CVE" ref_id="CVE-2010-3065" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3065.html"/>
        <reference source="CVE" ref_id="CVE-2010-3870" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3870.html"/>
        <description>The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:04.289-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:12.401-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:33.522-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="php-common is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:99858"/>
          <criterion comment="php-soap is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:99951"/>
          <criterion comment="php-odbc is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:99875"/>
          <criterion comment="php-gd is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:99873"/>
          <criterion comment="php-mysql is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:99753"/>
          <criterion comment="php is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:99828"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:99846"/>
          <criterion comment="php-cli is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:99484"/>
          <criterion comment="php-mbstring is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:99818"/>
          <criterion comment="php-pgsql is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:100002"/>
          <criterion comment="php-xml is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:99796"/>
          <criterion comment="php-dba is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:100017"/>
          <criterion comment="php-devel is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:99961"/>
          <criterion comment="php-bcmath is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:99934"/>
          <criterion comment="php-ncurses is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:99920"/>
          <criterion comment="php-imap is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:99879"/>
          <criterion comment="php-snmp is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:99682"/>
          <criterion comment="php-ldap is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:99959"/>
          <criterion comment="php-pdo is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:99918"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22021" version="81" class="patch">
      <metadata>
        <title>RHSA-2010:0625: wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0625-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0625.html"/>
        <reference source="CESA" ref_id="CESA-2010:0625"/>
        <reference source="CVE" ref_id="CVE-2010-1455" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1455.html"/>
        <reference source="CVE" ref_id="CVE-2010-2283" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2283.html"/>
        <reference source="CVE" ref_id="CVE-2010-2284" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2284.html"/>
        <reference source="CVE" ref_id="CVE-2010-2286" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2286.html"/>
        <reference source="CVE" ref_id="CVE-2010-2287" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2287.html"/>
        <reference source="CVE" ref_id="CVE-2010-2995" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2995.html"/>
        <description>The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:01.934-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:12.241-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:33.289-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="wireshark is earlier than 0:1.0.15-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99401"/>
          <criterion comment="wireshark-gnome is earlier than 0:1.0.15-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99540"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22020" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0565: w3m security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>w3m</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0565-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0565.html"/>
        <reference source="CESA" ref_id="CESA-2010:0565"/>
        <reference source="CVE" ref_id="CVE-2010-2074" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2074.html"/>
        <description>istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is enabled, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:28.453-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:12.172-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:33.194-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="w3m is earlier than 0:0.5.1-17.el5_5" test_ref="oval:org.mitre.oval:tst:99190"/>
          <criterion comment="w3m-img is earlier than 0:0.5.1-17.el5_5" test_ref="oval:org.mitre.oval:tst:98850"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22019" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1089: systemtap security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>systemtap</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1089-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1089.html"/>
        <reference source="CESA" ref_id="CESA-2011:1089"/>
        <reference source="CVE" ref_id="CVE-2011-2503" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2503.html"/>
        <description>The insert_module function in runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate a module when loading it, which allows local users to gain privileges via a race condition between the signature validation and the module initialization.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:07.545-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:12.083-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:33.085-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="systemtap-testsuite is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:97657"/>
          <criterion comment="systemtap-runtime is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:98330"/>
          <criterion comment="systemtap is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:98272"/>
          <criterion comment="systemtap-sdt-devel is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:97708"/>
          <criterion comment="systemtap-client is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:97549"/>
          <criterion comment="systemtap-initscript is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:98091"/>
          <criterion comment="systemtap-server is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:97954"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22016" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1317: cyrus-imapd security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>cyrus-imapd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1317-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1317.html"/>
        <reference source="CESA" ref_id="CESA-2011:1317"/>
        <reference source="CVE" ref_id="CVE-2011-3208" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3208.html"/>
        <description>Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a crafted NNTP command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:08.834-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:11.791-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:32.637-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:97968"/>
            <criterion comment="cyrus-imapd-perl is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:98476"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:98556"/>
            <criterion comment="cyrus-imapd is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:98033"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:98322"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:98340"/>
            <criterion comment="cyrus-imapd is earlier than 0:2.3.16-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:98308"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22014" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1343: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1343-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1343.html"/>
        <reference source="CESA" ref_id="CESA-2011:1343"/>
        <reference source="CVE" ref_id="CVE-2011-2998" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2998.html"/>
        <reference source="CVE" ref_id="CVE-2011-2999" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2999.html"/>
        <description>Mozilla Firefox before 3.6.23 and 4.x through 5, Thunderbird before 6.0, and SeaMonkey before 2.3 do not properly handle "location" as the name of a frame, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, a different vulnerability than CVE-2010-0170.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:02.181-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:11.708-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:32.504-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-26.el5_7" test_ref="oval:org.mitre.oval:tst:98191"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22013" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1438: thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1438-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1438.html"/>
        <reference source="CESA" ref_id="CESA-2011:1438"/>
        <reference source="CVE" ref_id="CVE-2011-3648" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3648.html"/>
        <description>Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 allows remote attackers to inject arbitrary web script or HTML via crafted text with Shift JIS encoding.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:54.275-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:11.635-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:32.417-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-27.el5_7" test_ref="oval:org.mitre.oval:tst:98373"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22011" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1455: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1455-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1455.html"/>
        <reference source="CESA" ref_id="CESA-2011:1455"/>
        <reference source="CVE" ref_id="CVE-2011-3439" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3439.html"/>
        <description>FreeType in CoreGraphics in Apple iOS before 5.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:10.802-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:11.557-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:32.313-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-28.el5_7.2" test_ref="oval:org.mitre.oval:tst:98793"/>
            <criterion comment="freetype is earlier than 0:2.2.1-28.el5_7.2" test_ref="oval:org.mitre.oval:tst:98461"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-28.el5_7.2" test_ref="oval:org.mitre.oval:tst:98490"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_1.8" test_ref="oval:org.mitre.oval:tst:98666"/>
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_1.8" test_ref="oval:org.mitre.oval:tst:98425"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_1.8" test_ref="oval:org.mitre.oval:tst:98484"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22010" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0321: automake security update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>automake</product>
          <product>automake14</product>
          <product>automake15</product>
          <product>automake16</product>
          <product>automake17</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0321-04" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0321.html"/>
        <reference source="CVE" ref_id="CVE-2009-4029" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4029.html"/>
        <description>The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, when producing a distribution tarball for a package that uses Automake, assign insecure permissions (777) to directories in the build tree, which introduces a race condition that allows local users to modify the contents of package files, introduce Trojan horse programs, or conduct other attacks before the build is complete.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:39.969-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:11.480-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:32.199-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="automake14 is earlier than 0:1.4p6-13.el5.1" test_ref="oval:org.mitre.oval:tst:99030"/>
          <criterion comment="automake15 is earlier than 0:1.5-16.el5.2" test_ref="oval:org.mitre.oval:tst:98899"/>
          <criterion comment="automake16 is earlier than 0:1.6.3-8.el5.1" test_ref="oval:org.mitre.oval:tst:99106"/>
          <criterion comment="automake17 is earlier than 0:1.7.9-7.el5.2" test_ref="oval:org.mitre.oval:tst:99218"/>
          <criterion comment="automake is earlier than 0:1.9.6-2.3.el5" test_ref="oval:org.mitre.oval:tst:99305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22009" version="237" class="patch">
      <metadata>
        <title>RHSA-2011:1384: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1384-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1384.html"/>
        <reference source="CVE" ref_id="CVE-2011-3389" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3389.html"/>
        <reference source="CVE" ref_id="CVE-2011-3516" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3516.html"/>
        <reference source="CVE" ref_id="CVE-2011-3521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3521.html"/>
        <reference source="CVE" ref_id="CVE-2011-3544" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3544.html"/>
        <reference source="CVE" ref_id="CVE-2011-3545" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3545.html"/>
        <reference source="CVE" ref_id="CVE-2011-3546" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3546.html"/>
        <reference source="CVE" ref_id="CVE-2011-3547" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3547.html"/>
        <reference source="CVE" ref_id="CVE-2011-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3548.html"/>
        <reference source="CVE" ref_id="CVE-2011-3549" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3549.html"/>
        <reference source="CVE" ref_id="CVE-2011-3550" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3550.html"/>
        <reference source="CVE" ref_id="CVE-2011-3551" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3551.html"/>
        <reference source="CVE" ref_id="CVE-2011-3552" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3552.html"/>
        <reference source="CVE" ref_id="CVE-2011-3553" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3553.html"/>
        <reference source="CVE" ref_id="CVE-2011-3554" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3554.html"/>
        <reference source="CVE" ref_id="CVE-2011-3556" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3556.html"/>
        <reference source="CVE" ref_id="CVE-2011-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3557.html"/>
        <reference source="CVE" ref_id="CVE-2011-3558" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3558.html"/>
        <reference source="CVE" ref_id="CVE-2011-3560" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3560.html"/>
        <reference source="CVE" ref_id="CVE-2011-3561" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3561.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JavaFX 2.0 allows remote attackers to affect confidentiality via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:15.834-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:11.034-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:31.592-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98228"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98371"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98250"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98614"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97901"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98149"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98537"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97694"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98552"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98603"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97996"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98142"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22008" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0792: kernel security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0792-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0792.html"/>
        <reference source="CESA" ref_id="CESA-2010:0792"/>
        <reference source="CVE" ref_id="CVE-2010-3904" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3904.html"/>
        <description>The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:23.803-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:10.923-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:31.471-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:98878"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:99740"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:99592"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:99790"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:99758"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:98858"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:99430"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:99307"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:99136"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:99381"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:99023"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:99802"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22006" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0926: bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind97</product>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0926-02" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0926.html"/>
        <reference source="CVE" ref_id="CVE-2011-2464" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2464.html"/>
        <reference source="CESA-2011:0926" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-July/017643.html" ref_id="CESA-2011:0926-CentOS 5"/>
        <description>Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before 9.7.3-P3, and 9.8.x before 9.8.0-P4 allows remote attackers to cause a denial of service (named daemon crash) via a crafted UPDATE request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:43.018-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:10.838-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:31.365-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22006 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:30.831-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:20.556-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind97 is earlier than 32:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:137289"/>
            <criterion comment="bind97-chroot is earlier than 32:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:137856"/>
            <criterion comment="bind97-devel is earlier than 32:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:137804"/>
            <criterion comment="bind97-libs is earlier than 32:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:137380"/>
            <criterion comment="bind97-utils is earlier than 32:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:137574"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 32:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:98241"/>
            <criterion comment="bind-chroot is earlier than 32:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:98104"/>
            <criterion comment="bind-debuginfo is earlier than 32:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:137310"/>
            <criterion comment="bind-devel is earlier than 32:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:97731"/>
            <criterion comment="bind-libs is earlier than 32:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:97693"/>
            <criterion comment="bind-sdb is earlier than 32:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:97308"/>
            <criterion comment="bind-utils is earlier than 32:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:97309"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22002" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1245: httpd security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1245-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1245.html"/>
        <reference source="CVE" ref_id="CVE-2011-3192" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3192.html"/>
        <description>The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:55.389-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:10.605-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:31.080-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-devel is earlier than 0:2.2.3-53.el5_7.1" test_ref="oval:org.mitre.oval:tst:98455"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-53.el5_7.1" test_ref="oval:org.mitre.oval:tst:97962"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-53.el5_7.1" test_ref="oval:org.mitre.oval:tst:98060"/>
            <criterion comment="httpd is earlier than 0:2.2.3-53.el5_7.1" test_ref="oval:org.mitre.oval:tst:98451"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-devel is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:98331"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:98122"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:98374"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:98108"/>
            <criterion comment="httpd is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:97781"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21999" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0679: rpm security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>rpm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0679-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0679.html"/>
        <reference source="CESA" ref_id="CESA-2010:0679"/>
        <reference source="CVE" ref_id="CVE-2010-2059" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2059.html"/>
        <description>lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before 4.4.3, does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:10.473-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:10.524-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:30.956-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="rpm-devel is earlier than 0:4.4.2.3-20.el5_5.1" test_ref="oval:org.mitre.oval:tst:99400"/>
          <criterion comment="rpm-python is earlier than 0:4.4.2.3-20.el5_5.1" test_ref="oval:org.mitre.oval:tst:99568"/>
          <criterion comment="rpm is earlier than 0:4.4.2.3-20.el5_5.1" test_ref="oval:org.mitre.oval:tst:99542"/>
          <criterion comment="rpm-libs is earlier than 0:4.4.2.3-20.el5_5.1" test_ref="oval:org.mitre.oval:tst:99526"/>
          <criterion comment="rpm-apidocs is earlier than 0:4.4.2.3-20.el5_5.1" test_ref="oval:org.mitre.oval:tst:99562"/>
          <criterion comment="popt is earlier than 0:1.10.2.3-20.el5_5.1" test_ref="oval:org.mitre.oval:tst:99600"/>
          <criterion comment="rpm-build is earlier than 0:4.4.2.3-20.el5_5.1" test_ref="oval:org.mitre.oval:tst:99094"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21997" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0793: glibc security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0793-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0793.html"/>
        <reference source="CESA" ref_id="CESA-2010:0793"/>
        <reference source="CVE" ref_id="CVE-2010-3856" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3856.html"/>
        <description>ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory, as demonstrated by libpcprofile.so.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:25.293-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:10.445-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:30.851-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="glibc-common is earlier than 0:2.5-49.el5_5.7" test_ref="oval:org.mitre.oval:tst:99793"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-49.el5_5.7" test_ref="oval:org.mitre.oval:tst:99696"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-49.el5_5.7" test_ref="oval:org.mitre.oval:tst:99800"/>
          <criterion comment="glibc is earlier than 0:2.5-49.el5_5.7" test_ref="oval:org.mitre.oval:tst:99461"/>
          <criterion comment="nscd is earlier than 0:2.5-49.el5_5.7" test_ref="oval:org.mitre.oval:tst:99738"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-49.el5_5.7" test_ref="oval:org.mitre.oval:tst:99467"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21996" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0698: samba3x security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>samba3x</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0698-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0698.html"/>
        <reference source="CESA" ref_id="CESA-2010:0698"/>
        <reference source="CVE" ref_id="CVE-2010-3069" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3069.html"/>
        <description>Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file share.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:40.503-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:10.353-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:30.728-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tdb-tools is earlier than 0:1.1.2-52.el5_5.2" test_ref="oval:org.mitre.oval:tst:99312"/>
          <criterion comment="samba3x-swat is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:99445"/>
          <criterion comment="libtdb is earlier than 0:1.1.2-52.el5_5.2" test_ref="oval:org.mitre.oval:tst:99167"/>
          <criterion comment="libtalloc-devel is earlier than 0:1.2.0-52.el5_5.2" test_ref="oval:org.mitre.oval:tst:99688"/>
          <criterion comment="samba3x-client is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:98821"/>
          <criterion comment="samba3x-doc is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:99599"/>
          <criterion comment="samba3x-winbind is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:99662"/>
          <criterion comment="samba3x is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:99725"/>
          <criterion comment="samba3x-winbind-devel is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:99607"/>
          <criterion comment="libtdb-devel is earlier than 0:1.1.2-52.el5_5.2" test_ref="oval:org.mitre.oval:tst:99718"/>
          <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:99727"/>
          <criterion comment="samba3x-common is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:99570"/>
          <criterion comment="libtalloc is earlier than 0:1.2.0-52.el5_5.2" test_ref="oval:org.mitre.oval:tst:99583"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21994" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1160: dhcp security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>dhcp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1160-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1160.html"/>
        <reference source="CESA" ref_id="CESA-2011:1160"/>
        <reference source="CVE" ref_id="CVE-2011-2748" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2748.html"/>
        <reference source="CVE" ref_id="CVE-2011-2749" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2749.html"/>
        <description>The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted BOOTP packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:59.187-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:10.240-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:30.597-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libdhcp4client is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:97914"/>
            <criterion comment="dhclient is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:98083"/>
            <criterion comment="dhcp-devel is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:98225"/>
            <criterion comment="dhcp is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:98139"/>
            <criterion comment="libdhcp4client-devel is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:98224"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dhclient is earlier than 12:4.1.1-19.P1.el6_1.1" test_ref="oval:org.mitre.oval:tst:97580"/>
            <criterion comment="dhcp-devel is earlier than 12:4.1.1-19.P1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98350"/>
            <criterion comment="dhcp is earlier than 12:4.1.1-19.P1.el6_1.1" test_ref="oval:org.mitre.oval:tst:97365"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21984" version="185" class="patch">
      <metadata>
        <title>RHSA-2011:1144: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1144-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1144.html"/>
        <reference source="CVE" ref_id="CVE-2011-2130" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2130.html"/>
        <reference source="CVE" ref_id="CVE-2011-2134" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2134.html"/>
        <reference source="CVE" ref_id="CVE-2011-2135" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2135.html"/>
        <reference source="CVE" ref_id="CVE-2011-2136" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2136.html"/>
        <reference source="CVE" ref_id="CVE-2011-2137" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2137.html"/>
        <reference source="CVE" ref_id="CVE-2011-2138" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2138.html"/>
        <reference source="CVE" ref_id="CVE-2011-2139" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2139.html"/>
        <reference source="CVE" ref_id="CVE-2011-2140" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2140.html"/>
        <reference source="CVE" ref_id="CVE-2011-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2414.html"/>
        <reference source="CVE" ref_id="CVE-2011-2415" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2415.html"/>
        <reference source="CVE" ref_id="CVE-2011-2416" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2416.html"/>
        <reference source="CVE" ref_id="CVE-2011-2417" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2417.html"/>
        <reference source="CVE" ref_id="CVE-2011-2424" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2424.html"/>
        <reference source="CVE" ref_id="CVE-2011-2425" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2425.html"/>
        <description>Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2135, CVE-2011-2140, and CVE-2011-2417.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:58.021-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:09.389-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:29.361-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.5-1.el5" test_ref="oval:org.mitre.oval:tst:97648"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.5-1.el6" test_ref="oval:org.mitre.oval:tst:98123"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21982" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0706: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0706-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0706.html"/>
        <reference source="CVE" ref_id="CVE-2010-2884" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2884.html"/>
        <description>Adobe Flash Player 10.1.82.76 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.92.10 on Android; authplay.dll in Adobe Reader and Acrobat 9.x before 9.4; and authplay.dll in Adobe Reader and Acrobat 8.x before 8.2.5 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in September 2010.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:15.971-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:09.217-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:29.130-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="flash-plugin is earlier than 0:10.1.85.3-1.el5" test_ref="oval:org.mitre.oval:tst:99678"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21981" version="133" class="patch">
      <metadata>
        <title>RHSA-2011:0938: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0938-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0938.html"/>
        <reference source="CVE" ref_id="CVE-2011-0802" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0802.html"/>
        <reference source="CVE" ref_id="CVE-2011-0814" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0814.html"/>
        <reference source="CVE" ref_id="CVE-2011-0862" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0862.html"/>
        <reference source="CVE" ref_id="CVE-2011-0863" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0863.html"/>
        <reference source="CVE" ref_id="CVE-2011-0865" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0865.html"/>
        <reference source="CVE" ref_id="CVE-2011-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0867.html"/>
        <reference source="CVE" ref_id="CVE-2011-0868" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0868.html"/>
        <reference source="CVE" ref_id="CVE-2011-0869" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0869.html"/>
        <reference source="CVE" ref_id="CVE-2011-0871" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0871.html"/>
        <reference source="CVE" ref_id="CVE-2011-0873" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0873.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, and 5.0 Update 29 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:15.995-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:08.965-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:28.740-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97311"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:98167"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:98087"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:98074"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97323"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97525"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97984"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:98262"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:97888"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:98315"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:98127"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:97859"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:98077"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:97953"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:98162"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21980" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0999: rsync security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>rsync</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0999-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0999.html"/>
        <reference source="CESA" ref_id="CESA-2011:0999"/>
        <reference source="CVE" ref_id="CVE-2007-6200" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6200.html"/>
        <description>Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclude_from, and filter and read or write hidden files via (1) symlink, (2) partial-dir, (3) backup-dir, and unspecified (4) dest options.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:53.946-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:08.839-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:28.625-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="rsync is earlier than 0:3.0.6-4.el5" test_ref="oval:org.mitre.oval:tst:98163"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21976" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1187: dovecot security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>dovecot</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1187-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1187.html"/>
        <reference source="CESA" ref_id="CESA-2011:1187"/>
        <reference source="CVE" ref_id="CVE-2011-1929" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1929.html"/>
        <description>lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:32.117-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:08.761-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:28.515-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="dovecot is earlier than 0:1.0.7-7.el5_7.1" test_ref="oval:org.mitre.oval:tst:98402"/>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dovecot-pgsql is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:98082"/>
            <criterion comment="dovecot-mysql is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:98088"/>
            <criterion comment="dovecot is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:98119"/>
            <criterion comment="dovecot-pigeonhole is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:98363"/>
            <criterion comment="dovecot-devel is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:98243"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21974" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:1811: netpbm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>netpbm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1811-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1811.html"/>
        <reference source="CESA" ref_id="CESA-2011:1811"/>
        <reference source="CVE" ref_id="CVE-2009-4274" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4274.html"/>
        <reference source="CVE" ref_id="CVE-2011-4516" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4516.html"/>
        <reference source="CVE" ref_id="CVE-2011-4517" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4517.html"/>
        <description>The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a denial of service (heap memory corruption), via a crafted component registration (CRG) marker segment in a JPEG2000 file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:05.403-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:08.568-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:28.236-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="netpbm-progs is earlier than 0:10.35.58-8.el5_7.3" test_ref="oval:org.mitre.oval:tst:98726"/>
          <criterion comment="netpbm-devel is earlier than 0:10.35.58-8.el5_7.3" test_ref="oval:org.mitre.oval:tst:98780"/>
          <criterion comment="netpbm is earlier than 0:10.35.58-8.el5_7.3" test_ref="oval:org.mitre.oval:tst:98605"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21967" version="120" class="patch">
      <metadata>
        <title>RHSA-2010:0504: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0504-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0504.html"/>
        <reference source="CESA" ref_id="CESA-2010:0504"/>
        <reference source="CVE" ref_id="CVE-2010-0291" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0291.html"/>
        <reference source="CVE" ref_id="CVE-2010-0622" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0622.html"/>
        <reference source="CVE" ref_id="CVE-2010-1087" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1087.html"/>
        <reference source="CVE" ref_id="CVE-2010-1088" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1088.html"/>
        <reference source="CVE" ref_id="CVE-2010-1173" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1173.html"/>
        <reference source="CVE" ref_id="CVE-2010-1187" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1187.html"/>
        <reference source="CVE" ref_id="CVE-2010-1436" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1436.html"/>
        <reference source="CVE" ref_id="CVE-2010-1437" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1437.html"/>
        <reference source="CVE" ref_id="CVE-2010-1641" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1641.html"/>
        <description>The do_gfs2_set_flags function in fs/gfs2/file.c in the Linux kernel before 2.6.34-git10 does not verify the ownership of a file, which allows local users to bypass intended access restrictions via a SETFLAGS ioctl request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:33.236-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:08.189-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:27.814-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:99588"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:99365"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:99554"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:99644"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:98852"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:99551"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:99102"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:99628"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:99417"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:99379"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:99326"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:99657"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21965" version="185" class="patch">
      <metadata>
        <title>RHSA-2011:0833: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0833-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0833.html"/>
        <reference source="CESA" ref_id="CESA-2011:0833"/>
        <reference source="CVE" ref_id="CVE-2011-0726" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0726.html"/>
        <reference source="CVE" ref_id="CVE-2011-1078" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1078.html"/>
        <reference source="CVE" ref_id="CVE-2011-1079" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1079.html"/>
        <reference source="CVE" ref_id="CVE-2011-1080" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1080.html"/>
        <reference source="CVE" ref_id="CVE-2011-1093" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1093.html"/>
        <reference source="CVE" ref_id="CVE-2011-1163" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1163.html"/>
        <reference source="CVE" ref_id="CVE-2011-1166" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1166.html"/>
        <reference source="CVE" ref_id="CVE-2011-1170" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1170.html"/>
        <reference source="CVE" ref_id="CVE-2011-1171" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1171.html"/>
        <reference source="CVE" ref_id="CVE-2011-1172" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1172.html"/>
        <reference source="CVE" ref_id="CVE-2011-1494" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1494.html"/>
        <reference source="CVE" ref_id="CVE-2011-1495" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1495.html"/>
        <reference source="CVE" ref_id="CVE-2011-1577" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1577.html"/>
        <reference source="CVE" ref_id="CVE-2011-1763" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1763.html"/>
        <description>The get_free_port function in Xen allows local authenticated DomU users to cause a denial of service or possibly gain privileges via unspecified vectors involving a new event channel port.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:02.065-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:07.674-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:27.430-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-238.12.1.el5" test_ref="oval:org.mitre.oval:tst:98048"/>
          <criterion comment="kernel is earlier than 0:2.6.18-238.12.1.el5" test_ref="oval:org.mitre.oval:tst:97529"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-238.12.1.el5" test_ref="oval:org.mitre.oval:tst:97477"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-238.12.1.el5" test_ref="oval:org.mitre.oval:tst:98066"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-238.12.1.el5" test_ref="oval:org.mitre.oval:tst:97771"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-238.12.1.el5" test_ref="oval:org.mitre.oval:tst:97898"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-238.12.1.el5" test_ref="oval:org.mitre.oval:tst:97991"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-238.12.1.el5" test_ref="oval:org.mitre.oval:tst:97680"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-238.12.1.el5" test_ref="oval:org.mitre.oval:tst:97999"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-238.12.1.el5" test_ref="oval:org.mitre.oval:tst:97977"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-238.12.1.el5" test_ref="oval:org.mitre.oval:tst:97467"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-238.12.1.el5" test_ref="oval:org.mitre.oval:tst:97822"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21964" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0347: nss_db security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>nss_db</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0347-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0347.html"/>
        <reference source="CESA" ref_id="CESA-2010:0347"/>
        <reference source="CVE" ref_id="CVE-2010-0826" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0826.html"/>
        <description>The Free Software Foundation (FSF) Berkeley DB NSS module (aka libnss-db) 2.2.3pre1 reads the DB_CONFIG file in the current working directory, which allows local users to obtain sensitive information via a symlink attack involving a setgid or setuid application that uses this module.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:03.229-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:07.605-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:27.336-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="nss_db is earlier than 0:2.2-35.4.el5_5" test_ref="oval:org.mitre.oval:tst:98890"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21961" version="5" class="patch">
      <metadata>
        <title>RHSA-2011:1267: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1267-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1267.html"/>
        <reference source="CESA" ref_id="CESA-2011:1267"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

The RHSA-2011:1243 Thunderbird update rendered HTTPS certificates signed by
a certain Certificate Authority (CA) as untrusted, but made an exception
for a select few. This update removes that exception, rendering every HTTPS
certificate signed by that CA as untrusted. (BZ#735483)

All Thunderbird users should upgrade to this updated package, which
resolves this issue. All running instances of Thunderbird must be
restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:02.709-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:07.482-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:27.181-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21961 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:39.221-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:41.839-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:2.0.0.24-25.el5" test_ref="oval:org.mitre.oval:tst:97929"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="thunderbird is earlier than 0:3.1.14-1.el6_1" test_ref="oval:org.mitre.oval:tst:97563"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21960" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0436: avahi security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>avahi</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0436-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0436.html"/>
        <reference source="CESA" ref_id="CESA-2011:0436"/>
        <reference source="CVE" ref_id="CVE-2011-1002" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1002.html"/>
        <description>avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to port 5353.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-2244.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:51.868-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:07.389-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:27.073-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="avahi-compat-howl is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:97605"/>
          <criterion comment="avahi-glib-devel is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:97746"/>
          <criterion comment="avahi is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:97856"/>
          <criterion comment="avahi-compat-howl-devel is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:97861"/>
          <criterion comment="avahi-compat-libdns_sd is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:97554"/>
          <criterion comment="avahi-glib is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:97727"/>
          <criterion comment="avahi-qt3 is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:97789"/>
          <criterion comment="avahi-tools is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:97476"/>
          <criterion comment="avahi-qt3-devel is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:97390"/>
          <criterion comment="avahi-compat-libdns_sd-devel is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:97871"/>
          <criterion comment="avahi-devel is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:97158"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21955" version="5" class="patch">
      <metadata>
        <title>RHSA-2011:1401: xen security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1401-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1401.html"/>
        <reference source="CESA" ref_id="CESA-2011:1401"/>
        <reference source="CVE" ref_id="CVE-2011-3346" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3346.html"/>
        <description>Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted SAI READ CAPACITY SCSI command.  NOTE: this is only a vulnerability when root has manually modified certain permissions or ACLs.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:59.752-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:07.021-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:26.680-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="xen is earlier than 0:3.0.3-132.el5_7.2" test_ref="oval:org.mitre.oval:tst:98137"/>
          <criterion comment="xen-libs is earlier than 0:3.0.3-132.el5_7.2" test_ref="oval:org.mitre.oval:tst:98676"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-132.el5_7.2" test_ref="oval:org.mitre.oval:tst:98505"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21954" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1073: bash security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bash</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1073-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1073.html"/>
        <reference source="CESA" ref_id="CESA-2011:1073"/>
        <reference source="CVE" ref_id="CVE-2008-5374" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5374.html"/>
        <description>bash-doc 3.2 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/cb#####.? temporary file, related to the (1) aliasconv.sh, (2) aliasconv.bash, and (3) cshtobash scripts.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:03.311-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:06.929-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:26.596-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="bash is earlier than 0:3.2-32.el5" test_ref="oval:org.mitre.oval:tst:97933"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21953" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1104: libpng security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>libpng</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1104-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1104.html"/>
        <reference source="CESA" ref_id="CESA-2011:1104"/>
        <reference source="CVE" ref_id="CVE-2011-2690" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2690.html"/>
        <reference source="CVE" ref_id="CVE-2011-2692" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2692.html"/>
        <description>The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not properly handle invalid sCAL chunks, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted PNG image that triggers the reading of uninitialized memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:03.687-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:06.818-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:26.464-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libpng is earlier than 2:1.2.10-7.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:98153"/>
          <criterion comment="libpng-devel is earlier than 2:1.2.10-7.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:98247"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21950" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1402: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1402-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1402.html"/>
        <reference source="CESA" ref_id="CESA-2011:1402"/>
        <reference source="CVE" ref_id="CVE-2011-3256" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3256.html"/>
        <description>FreeType 2 before 2.4.7, as used in CoreGraphics in Apple iOS before 5, Mandriva Enterprise Server 5, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font, a different vulnerability than CVE-2011-0226.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:06.540-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:06.500-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:26.110-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-28.el5_7.1" test_ref="oval:org.mitre.oval:tst:98660"/>
            <criterion comment="freetype is earlier than 0:2.2.1-28.el5_7.1" test_ref="oval:org.mitre.oval:tst:98536"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-28.el5_7.1" test_ref="oval:org.mitre.oval:tst:98188"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_1.7" test_ref="oval:org.mitre.oval:tst:98700"/>
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_1.7" test_ref="oval:org.mitre.oval:tst:98065"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_1.7" test_ref="oval:org.mitre.oval:tst:98563"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21948" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0002: PyXML security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>PyXML</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0002-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0002.html"/>
        <reference source="CESA" ref_id="CESA-2010:0002"/>
        <reference source="CVE" ref_id="CVE-2009-3720" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3720.html"/>
        <description>The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:24.517-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:06.286-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:25.863-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="PyXML is earlier than 0:0.8.4-4.el5_4.2" test_ref="oval:org.mitre.oval:tst:98632"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21947" version="146" class="patch">
      <metadata>
        <title>RHSA-2010:0966: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0966-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0966.html"/>
        <reference source="CVE" ref_id="CVE-2010-3766" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3766.html"/>
        <reference source="CVE" ref_id="CVE-2010-3767" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3767.html"/>
        <reference source="CVE" ref_id="CVE-2010-3768" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3768.html"/>
        <reference source="CVE" ref_id="CVE-2010-3770" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3770.html"/>
        <reference source="CVE" ref_id="CVE-2010-3771" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3771.html"/>
        <reference source="CVE" ref_id="CVE-2010-3772" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3772.html"/>
        <reference source="CVE" ref_id="CVE-2010-3773" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3773.html"/>
        <reference source="CVE" ref_id="CVE-2010-3774" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3774.html"/>
        <reference source="CVE" ref_id="CVE-2010-3775" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3775.html"/>
        <reference source="CVE" ref_id="CVE-2010-3776" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3776.html"/>
        <reference source="CVE" ref_id="CVE-2010-3777" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3777.html"/>
        <description>Unspecified vulnerability in Mozilla Firefox 3.6.x before 3.6.13 and Thunderbird 3.1.x before 3.1.7 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:39.335-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:06.022-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:25.535-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.13-3.el5" test_ref="oval:org.mitre.oval:tst:99608"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.13-3.el5" test_ref="oval:org.mitre.oval:tst:99983"/>
            <criterion comment="firefox is earlier than 0:3.6.13-2.el5" test_ref="oval:org.mitre.oval:tst:99947"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.13-3.el6_0" test_ref="oval:org.mitre.oval:tst:100121"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.13-3.el6_0" test_ref="oval:org.mitre.oval:tst:100021"/>
            <criterion comment="firefox is earlier than 0:3.6.13-2.el6_0" test_ref="oval:org.mitre.oval:tst:100126"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21944" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1459: bind97 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1459-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1459.html"/>
        <reference source="CESA" ref_id="CESA-2011:1459"/>
        <reference source="CVE" ref_id="CVE-2011-4313" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4313.html"/>
        <description>query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named exit) via unknown vectors related to recursive DNS queries, error logging, and the caching of an invalid record by the resolver.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:27.982-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:05.874-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:25.334-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="bind97-utils is earlier than 32:9.7.0-6.P2.el5_7.4" test_ref="oval:org.mitre.oval:tst:98757"/>
          <criterion comment="bind97-libs is earlier than 32:9.7.0-6.P2.el5_7.4" test_ref="oval:org.mitre.oval:tst:98762"/>
          <criterion comment="bind97-chroot is earlier than 32:9.7.0-6.P2.el5_7.4" test_ref="oval:org.mitre.oval:tst:98464"/>
          <criterion comment="bind97 is earlier than 32:9.7.0-6.P2.el5_7.4" test_ref="oval:org.mitre.oval:tst:98761"/>
          <criterion comment="bind97-devel is earlier than 32:9.7.0-6.P2.el5_7.4" test_ref="oval:org.mitre.oval:tst:98578"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21943" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0039: gcc and gcc4 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gcc</product>
          <product>gcc4</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0039-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0039.html"/>
        <reference source="CESA" ref_id="CESA-2010:0039"/>
        <reference source="CVE" ref_id="CVE-2009-3736" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3736.html"/>
        <description>ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:24.427-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:05.766-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:25.195-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="gcc-objc++ is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:98717"/>
          <criterion comment="libgfortran is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:98169"/>
          <criterion comment="libgcj-src is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:98823"/>
          <criterion comment="libmudflap is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:98106"/>
          <criterion comment="gcc-gfortran is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:98791"/>
          <criterion comment="libgcj-devel is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:98759"/>
          <criterion comment="libgcc is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:98851"/>
          <criterion comment="cpp is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:99084"/>
          <criterion comment="gcc-gnat is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:99151"/>
          <criterion comment="libstdc++ is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:98502"/>
          <criterion comment="libmudflap-devel is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:98957"/>
          <criterion comment="gcc-objc is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:98795"/>
          <criterion comment="gcc-c++ is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:98971"/>
          <criterion comment="gcc is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:98988"/>
          <criterion comment="gcc-java is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:98186"/>
          <criterion comment="libgnat is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:99008"/>
          <criterion comment="libgcj is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:98935"/>
          <criterion comment="libstdc++-devel is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:98334"/>
          <criterion comment="libobjc is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:98720"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21942" version="198" class="patch">
      <metadata>
        <title>RHSA-2010:0339: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0339-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0339.html"/>
        <reference source="CESA" ref_id="CESA-2010:0339"/>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html"/>
        <reference source="CVE" ref_id="CVE-2010-0082" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0082.html"/>
        <reference source="CVE" ref_id="CVE-2010-0084" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0084.html"/>
        <reference source="CVE" ref_id="CVE-2010-0085" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0085.html"/>
        <reference source="CVE" ref_id="CVE-2010-0088" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0088.html"/>
        <reference source="CVE" ref_id="CVE-2010-0091" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0091.html"/>
        <reference source="CVE" ref_id="CVE-2010-0092" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0092.html"/>
        <reference source="CVE" ref_id="CVE-2010-0093" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0093.html"/>
        <reference source="CVE" ref_id="CVE-2010-0094" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0094.html"/>
        <reference source="CVE" ref_id="CVE-2010-0095" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0095.html"/>
        <reference source="CVE" ref_id="CVE-2010-0837" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0837.html"/>
        <reference source="CVE" ref_id="CVE-2010-0838" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0838.html"/>
        <reference source="CVE" ref_id="CVE-2010-0840" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0840.html"/>
        <reference source="CVE" ref_id="CVE-2010-0845" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0845.html"/>
        <reference source="CVE" ref_id="CVE-2010-0847" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0847.html"/>
        <reference source="CVE" ref_id="CVE-2010-0848" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0848.html"/>
        <description>Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:14.953-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:05.414-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:24.480-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:99038"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:99169"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:98904"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:98792"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:99335"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21941" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1359: xorg-x11-server security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1359-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1359.html"/>
        <reference source="CESA" ref_id="CESA-2011:1359"/>
        <reference source="CVE" ref_id="CVE-2010-4818" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4818.html"/>
        <reference source="CVE" ref_id="CVE-2010-4819" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4819.html"/>
        <description>The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:50.531-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:05.293-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:24.262-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:98548"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:98052"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:98513"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:97946"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:98353"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:98602"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:98218"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:98585"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:98416"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:98092"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:98622"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:98509"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:97660"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:98366"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:98518"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:97703"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:98579"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21940" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0844: apr security update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>apr</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0844-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0844.html"/>
        <reference source="CESA" ref_id="CESA-2011:0844"/>
        <reference source="CVE" ref_id="CVE-2011-1928" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1928.html"/>
        <description>The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecified types of wildcard patterns, as demonstrated by attacks against mod_autoindex in httpd when a /*/WEB-INF/ configuration pattern is used.  NOTE: this issue exists because of an incorrect fix for CVE-2011-0419.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:04.635-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:05.199-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:24.141-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="apr-devel is earlier than 0:1.2.7-11.el5_6.5" test_ref="oval:org.mitre.oval:tst:97722"/>
            <criterion comment="apr-docs is earlier than 0:1.2.7-11.el5_6.5" test_ref="oval:org.mitre.oval:tst:98056"/>
            <criterion comment="apr is earlier than 0:1.2.7-11.el5_6.5" test_ref="oval:org.mitre.oval:tst:98041"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="apr-devel is earlier than 0:1.3.9-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:97827"/>
            <criterion comment="apr is earlier than 0:1.3.9-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:97916"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21939" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0372: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0372-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0372.html"/>
        <reference source="CVE" ref_id="CVE-2011-0609" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0609.html"/>
        <description>Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:30.268-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:05.119-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:24.051-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.2.153.1-1.el5" test_ref="oval:org.mitre.oval:tst:97654"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.2.153.1-1.el6" test_ref="oval:org.mitre.oval:tst:97632"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21936" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:1065: Red Hat Enterprise Linux 5.7 kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1065-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1065.html"/>
        <reference source="CESA" ref_id="CESA-2011:1065"/>
        <reference source="CVE" ref_id="CVE-2011-1780" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1780.html"/>
        <reference source="CVE" ref_id="CVE-2011-2525" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2525.html"/>
        <reference source="CVE" ref_id="CVE-2011-2689" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2689.html"/>
        <description>The gfs2_fallocate function in fs/gfs2/file.c in the Linux kernel before 3.0-rc1 does not ensure that the size of a chunk allocation is a multiple of the block size, which allows local users to cause a denial of service (BUG and system crash) by arranging for all resource groups to have too little free space.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:34.839-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:04.945-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:23.889-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:98155"/>
          <criterion comment="kernel is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:98156"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:97575"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:98063"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:98103"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:98219"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:98318"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:97998"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:98320"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:98080"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:98014"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:98094"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21935" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0459: openoffice.org security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openoffice.org</product>
          <product>openoffice.org2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0459-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0459.html"/>
        <reference source="CESA" ref_id="CESA-2010:0459"/>
        <reference source="CVE" ref_id="CVE-2010-0395" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0395.html"/>
        <description>OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution when the macro directory structure is previewed.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:30.609-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:04.630-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:23.632-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openoffice.org is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99352"/>
          <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99109"/>
          <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99080"/>
          <criterion comment="openoffice.org-ure is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99064"/>
          <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99339"/>
          <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99399"/>
          <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99308"/>
          <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99411"/>
          <criterion comment="openoffice.org-calc is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99424"/>
          <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:98841"/>
          <criterion comment="openoffice.org-langpack-nl is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99436"/>
          <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99225"/>
          <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99176"/>
          <criterion comment="openoffice.org-testtools is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99062"/>
          <criterion comment="openoffice.org-headless is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99209"/>
          <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99420"/>
          <criterion comment="openoffice.org-langpack-it is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99328"/>
          <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99331"/>
          <criterion comment="openoffice.org-base is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99184"/>
          <criterion comment="openoffice.org-draw is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:98926"/>
          <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99306"/>
          <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99066"/>
          <criterion comment="openoffice.org-langpack-es is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99453"/>
          <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99377"/>
          <criterion comment="openoffice.org-langpack-ar is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99380"/>
          <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99344"/>
          <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99296"/>
          <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99191"/>
          <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:98703"/>
          <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99276"/>
          <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99144"/>
          <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:98979"/>
          <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99406"/>
          <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99340"/>
          <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99454"/>
          <criterion comment="openoffice.org-langpack-ru is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:98770"/>
          <criterion comment="openoffice.org-xsltfilter is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:98728"/>
          <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99236"/>
          <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99382"/>
          <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99362"/>
          <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99289"/>
          <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:98456"/>
          <criterion comment="openoffice.org-langpack-bn is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99374"/>
          <criterion comment="openoffice.org-graphicfilter is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99219"/>
          <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99153"/>
          <criterion comment="openoffice.org-pyuno is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99402"/>
          <criterion comment="openoffice.org-writer is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99304"/>
          <criterion comment="openoffice.org-langpack-fr is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99273"/>
          <criterion comment="openoffice.org-sdk is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99438"/>
          <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99295"/>
          <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99360"/>
          <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99432"/>
          <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99125"/>
          <criterion comment="openoffice.org-langpack-ur is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99349"/>
          <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99408"/>
          <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99180"/>
          <criterion comment="openoffice.org-math is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99045"/>
          <criterion comment="openoffice.org-core is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99452"/>
          <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99336"/>
          <criterion comment="openoffice.org-impress is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99444"/>
          <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99046"/>
          <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99201"/>
          <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99361"/>
          <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99403"/>
          <criterion comment="openoffice.org-sdk-doc is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99294"/>
          <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:98942"/>
          <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99059"/>
          <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99215"/>
          <criterion comment="openoffice.org-emailmerge is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99058"/>
          <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99299"/>
          <criterion comment="openoffice.org-javafilter is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99131"/>
          <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:98802"/>
          <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99314"/>
          <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99386"/>
          <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99245"/>
          <criterion comment="openoffice.org-langpack-sv is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:99383"/>
          <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:98670"/>
          <criterion comment="openoffice.org-langpack-de is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:98695"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21931" version="83" class="patch">
      <metadata>
        <title>RHSA-2011:0281: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0281-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0281.html"/>
        <reference source="CVE" ref_id="CVE-2010-4448" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4448.html"/>
        <reference source="CVE" ref_id="CVE-2010-4450" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4450.html"/>
        <reference source="CVE" ref_id="CVE-2010-4465" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4465.html"/>
        <reference source="CVE" ref_id="CVE-2010-4469" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4469.html"/>
        <reference source="CVE" ref_id="CVE-2010-4470" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4470.html"/>
        <reference source="CVE" ref_id="CVE-2010-4472" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4472.html"/>
        <reference source="CESA-2011:0281" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017313.html" ref_id="CESA-2011:0281-CentOS 5"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier allows remote attackers to affect availability, related to XML Digital Signature and unspecified APIs.  NOTE: the previous information was obtained from the February 2011 CPU.  Oracle has not commented on claims from a downstream vendor that this issue involves the replacement of the "XML DSig Transform or C14N algorithm implementations."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:54.841-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:03.920-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:23.024-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21931 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:23.744-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:19.756-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.20.b17.el5" test_ref="oval:org.mitre.oval:tst:137485"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.20.b17.el5" test_ref="oval:org.mitre.oval:tst:137829"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.20.b17.el5" test_ref="oval:org.mitre.oval:tst:137774"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.20.b17.el5" test_ref="oval:org.mitre.oval:tst:137864"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.20.b17.el5" test_ref="oval:org.mitre.oval:tst:137586"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:97082"/>
            <criterion comment="java-1.6.0-openjdk-debuginfo is earlier than 1:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:137660"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:96965"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:97425"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:97074"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:97073"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21929" version="3" class="patch">
      <metadata>
        <title>RHSA-2011:1444: nss security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1444-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1444.html"/>
        <reference source="CESA" ref_id="CESA-2011:1444"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the development of security-enabled client and server applications.

It was found that the Malaysia-based Digicert Sdn. Bhd. subordinate
Certificate Authority (CA) issued HTTPS certificates with weak keys. This
update renders any HTTPS certificates signed by that CA as untrusted. This
covers all uses of the certificates, including SSL, S/MIME, and code
signing. Note: Digicert Sdn. Bhd. is not the same company as found at
digicert.com. (BZ#751366)

Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.

This update also fixes the following bug on Red Hat Enterprise Linux 5:

* When using mod_nss with the Apache HTTP Server, a bug in NSS on Red Hat
Enterprise Linux 5 resulted in file descriptors leaking each time the
Apache HTTP Server was restarted with the "service httpd reload" command.
This could have prevented the Apache HTTP Server from functioning properly
if all available file descriptors were consumed. (BZ#743508)

For Red Hat Enterprise Linux 6, these updated packages upgrade NSS to
version 3.12.10. As well, they upgrade NSPR (Netscape Portable Runtime) to
version 4.8.8 and nss-util to version 3.12.10 on Red Hat
Enterprise Linux 6, as required by the NSS update. (BZ#735972, BZ#736272,
BZ#735973)

All NSS users should upgrade to these updated packages, which correct this
issue. After installing the update, applications using NSS must be
restarted for the changes to take effect. In addition, on Red Hat
Enterprise Linux 6, applications using NSPR and nss-util must also be
restarted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:00.628-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:03.737-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:22.804-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="nss-tools is earlier than 0:3.12.10-7.el5_7" test_ref="oval:org.mitre.oval:tst:97792"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.10-7.el5_7" test_ref="oval:org.mitre.oval:tst:98627"/>
            <criterion comment="nss is earlier than 0:3.12.10-7.el5_7" test_ref="oval:org.mitre.oval:tst:98465"/>
            <criterion comment="nss-devel is earlier than 0:3.12.10-7.el5_7" test_ref="oval:org.mitre.oval:tst:98752"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="nss-tools is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:98434"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:98650"/>
            <criterion comment="nss-sysinit is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:98789"/>
            <criterion comment="nss is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:98531"/>
            <criterion comment="nss-devel is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:98626"/>
            <criterion comment="nspr is earlier than 0:4.8.8-1.el6_1" test_ref="oval:org.mitre.oval:tst:98760"/>
            <criterion comment="nspr-devel is earlier than 0:4.8.8-1.el6_1" test_ref="oval:org.mitre.oval:tst:98738"/>
            <criterion comment="nss-util is earlier than 0:3.12.10-1.el6_1" test_ref="oval:org.mitre.oval:tst:98621"/>
            <criterion comment="nss-util-devel is earlier than 0:3.12.10-1.el6_1" test_ref="oval:org.mitre.oval:tst:98540"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21927" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0496: xen security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0496-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0496.html"/>
        <reference source="CESA" ref_id="CESA-2011:0496"/>
        <reference source="CVE" ref_id="CVE-2011-1583" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1583.html"/>
        <description>Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow local users to cause a denial of service and possibly execute arbitrary code via a crafted paravirtualised guest kernel image that triggers (1) a buffer overflow during a decompression loop or (2) an out-of-bounds read in the loader involving unspecified length fields.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:07.401-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:03.554-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:22.464-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="xen is earlier than 0:3.0.3-120.el5_6.2" test_ref="oval:org.mitre.oval:tst:97408"/>
          <criterion comment="xen-libs is earlier than 0:3.0.3-120.el5_6.2" test_ref="oval:org.mitre.oval:tst:97785"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-120.el5_6.2" test_ref="oval:org.mitre.oval:tst:97864"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21925" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0975: sssd security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>sssd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0975-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0975.html"/>
        <reference source="CESA" ref_id="CESA-2011:0975"/>
        <reference source="CVE" ref_id="CVE-2010-4341" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4341.html"/>
        <description>The pam_parse_in_data_v2 function in src/responder/pam/pamsrv_cmd.c in the PAM responder in SSSD 1.5.0, 1.4.x, and 1.3 allows local users to cause a denial of service (infinite loop, crash, and login prevention) via a crafted packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:18.558-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:03.468-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:22.344-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="sssd is earlier than 0:1.5.1-37.el5" test_ref="oval:org.mitre.oval:tst:98166"/>
          <criterion comment="sssd-client is earlier than 0:1.5.1-37.el5" test_ref="oval:org.mitre.oval:tst:98098"/>
          <criterion comment="sssd-tools is earlier than 0:1.5.1-37.el5" test_ref="oval:org.mitre.oval:tst:98215"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21923" version="55" class="patch">
      <metadata>
        <title>RHSA-2011:0492: python security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>python</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0492-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0492.html"/>
        <reference source="CESA" ref_id="CESA-2011:0492"/>
        <reference source="CVE" ref_id="CVE-2009-3720" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3720.html"/>
        <reference source="CVE" ref_id="CVE-2010-3493" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3493.html"/>
        <reference source="CVE" ref_id="CVE-2011-1015" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1015.html"/>
        <reference source="CVE" ref_id="CVE-2011-1521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1521.html"/>
        <description>The urllib and urllib2 modules in Python 2.x before 2.7.2 and 3.x before 3.2.1 process Location headers that specify redirection to file: URLs, which makes it easier for remote attackers to obtain sensitive information or cause a denial of service (resource consumption) via a crafted URL, as demonstrated by the file:///etc/passwd and file:///dev/zero URLs.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:53.455-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:02.820-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:21.541-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="python-devel is earlier than 0:2.4.3-44.el5" test_ref="oval:org.mitre.oval:tst:97690"/>
          <criterion comment="python-libs is earlier than 0:2.4.3-44.el5" test_ref="oval:org.mitre.oval:tst:97763"/>
          <criterion comment="tkinter is earlier than 0:2.4.3-44.el5" test_ref="oval:org.mitre.oval:tst:97300"/>
          <criterion comment="python is earlier than 0:2.4.3-44.el5" test_ref="oval:org.mitre.oval:tst:97527"/>
          <criterion comment="python-tools is earlier than 0:2.4.3-44.el5" test_ref="oval:org.mitre.oval:tst:97836"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21921" version="81" class="patch">
      <metadata>
        <title>RHSA-2011:0027: python security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>python</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0027-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0027.html"/>
        <reference source="CVE" ref_id="CVE-2008-5983" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5983.html"/>
        <reference source="CVE" ref_id="CVE-2009-4134" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4134.html"/>
        <reference source="CVE" ref_id="CVE-2010-1449" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1449.html"/>
        <reference source="CVE" ref_id="CVE-2010-1450" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1450.html"/>
        <reference source="CVE" ref_id="CVE-2010-1634" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1634.html"/>
        <reference source="CVE" ref_id="CVE-2010-2089" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2089.html"/>
        <description>The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string lengths, which allows context-dependent attackers to cause a denial of service (memory corruption and application crash) via crafted arguments, as demonstrated by a call to audioop.reverse with a one-byte string, a different vulnerability than CVE-2010-1634.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:30.878-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:02.532-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:21.124-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="python-devel is earlier than 0:2.4.3-43.el5" test_ref="oval:org.mitre.oval:tst:96701"/>
          <criterion comment="python-libs is earlier than 0:2.4.3-43.el5" test_ref="oval:org.mitre.oval:tst:96170"/>
          <criterion comment="tkinter is earlier than 0:2.4.3-43.el5" test_ref="oval:org.mitre.oval:tst:97027"/>
          <criterion comment="python is earlier than 0:2.4.3-43.el5" test_ref="oval:org.mitre.oval:tst:96428"/>
          <criterion comment="python-tools is earlier than 0:2.4.3-43.el5" test_ref="oval:org.mitre.oval:tst:96648"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21920" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0506: rdesktop security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>rdesktop</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0506-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0506.html"/>
        <reference source="CVE" ref_id="CVE-2011-1595" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1595.html"/>
        <reference source="CESA-2011:0506" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-May/017557.html" ref_id="CESA-2011:0506-CentOS 5"/>
        <description>Directory traversal vulnerability in the disk_create function in disk.c in rdesktop before 1.7.0, when disk redirection is enabled, allows remote RDP servers to read or overwrite arbitrary files via a .. (dot dot) in a pathname.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:56.057-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:02.464-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:21.040-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21920 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:24.338-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:19.398-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="rdesktop is earlier than 0:1.6.0-3.el5_6.2" test_ref="oval:org.mitre.oval:tst:137607"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="rdesktop is earlier than 0:1.6.0-8.el6_0.1" test_ref="oval:org.mitre.oval:tst:97721"/>
            <criterion comment="rdesktop-debuginfo is earlier than 0:1.6.0-8.el6_0.1" test_ref="oval:org.mitre.oval:tst:137855"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21919" version="55" class="patch">
      <metadata>
        <title>RHSA-2010:0101: openoffice.org security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openoffice.org</product>
          <product>openoffice.org2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0101-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0101.html"/>
        <reference source="CESA" ref_id="CESA-2010:0101"/>
        <reference source="CVE" ref_id="CVE-2009-2949" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2949.html"/>
        <reference source="CVE" ref_id="CVE-2009-2950" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2950.html"/>
        <reference source="CVE" ref_id="CVE-2009-3301" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3301.html"/>
        <reference source="CVE" ref_id="CVE-2009-3302" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3302.html"/>
        <description>filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTSetBrc table property modifier in a Word document, related to a "boundary error flaw."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:53.840-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:02.145-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:20.637-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98284"/>
          <criterion comment="openoffice.org is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99100"/>
          <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98594"/>
          <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99006"/>
          <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99071"/>
          <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98394"/>
          <criterion comment="openoffice.org-calc is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99122"/>
          <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98960"/>
          <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99019"/>
          <criterion comment="openoffice.org-langpack-nl is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99165"/>
          <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98663"/>
          <criterion comment="openoffice.org-headless is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99206"/>
          <criterion comment="openoffice.org-testtools is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98764"/>
          <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98846"/>
          <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98508"/>
          <criterion comment="openoffice.org-langpack-it is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99065"/>
          <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99028"/>
          <criterion comment="openoffice.org-base is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98697"/>
          <criterion comment="openoffice.org-draw is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99239"/>
          <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98767"/>
          <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98777"/>
          <criterion comment="openoffice.org-langpack-es is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98645"/>
          <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99002"/>
          <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99049"/>
          <criterion comment="openoffice.org-langpack-ar is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98993"/>
          <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99103"/>
          <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99211"/>
          <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98994"/>
          <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98442"/>
          <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99221"/>
          <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99205"/>
          <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99050"/>
          <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98844"/>
          <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98574"/>
          <criterion comment="openoffice.org-langpack-ru is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98901"/>
          <criterion comment="openoffice.org-xsltfilter is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99105"/>
          <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99212"/>
          <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99021"/>
          <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99203"/>
          <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98934"/>
          <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98246"/>
          <criterion comment="openoffice.org-langpack-bn is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99000"/>
          <criterion comment="openoffice.org-graphicfilter is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98440"/>
          <criterion comment="openoffice.org-pyuno is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99117"/>
          <criterion comment="openoffice.org-writer is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99041"/>
          <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99026"/>
          <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98953"/>
          <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98868"/>
          <criterion comment="openoffice.org-sdk is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98675"/>
          <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99177"/>
          <criterion comment="openoffice.org-langpack-fr is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98564"/>
          <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99044"/>
          <criterion comment="openoffice.org-math is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99047"/>
          <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99091"/>
          <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99188"/>
          <criterion comment="openoffice.org-langpack-ur is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99112"/>
          <criterion comment="openoffice.org-core is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99158"/>
          <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99009"/>
          <criterion comment="openoffice.org-impress is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99157"/>
          <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99149"/>
          <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98825"/>
          <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99242"/>
          <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99024"/>
          <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98955"/>
          <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99135"/>
          <criterion comment="openoffice.org-sdk-doc is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99230"/>
          <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98916"/>
          <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98939"/>
          <criterion comment="openoffice.org-emailmerge is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99217"/>
          <criterion comment="openoffice.org-javafilter is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99152"/>
          <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98692"/>
          <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98998"/>
          <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99040"/>
          <criterion comment="openoffice.org-langpack-sv is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98745"/>
          <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99150"/>
          <criterion comment="openoffice.org-langpack-de is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:99097"/>
          <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:98755"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21917" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:0025: gcc security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>gcc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0025-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0025.html"/>
        <reference source="CVE" ref_id="CVE-2010-0831" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0831.html"/>
        <reference source="CVE" ref_id="CVE-2010-2322" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2322.html"/>
        <description>Absolute path traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a full pathname for a file within a .jar archive, a related issue to CVE-2010-0831.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-3619.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:20.525-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:02.016-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:20.447-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libgcj-src is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:97071"/>
          <criterion comment="gcc-objc++ is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:97047"/>
          <criterion comment="libgfortran is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:96675"/>
          <criterion comment="libmudflap is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:96985"/>
          <criterion comment="gcc-gfortran is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:96280"/>
          <criterion comment="libgcc is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:96759"/>
          <criterion comment="libgcj-devel is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:97072"/>
          <criterion comment="cpp is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:97079"/>
          <criterion comment="gcc-gnat is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:97029"/>
          <criterion comment="libstdc++ is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:97054"/>
          <criterion comment="libmudflap-devel is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:97009"/>
          <criterion comment="gcc-objc is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:96430"/>
          <criterion comment="gcc-c++ is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:96393"/>
          <criterion comment="gcc is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:96912"/>
          <criterion comment="gcc-java is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:97030"/>
          <criterion comment="libgnat is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:96398"/>
          <criterion comment="libgcj is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:96489"/>
          <criterion comment="libstdc++-devel is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:96222"/>
          <criterion comment="libobjc is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:96818"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21916" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0478: libvirt security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0478-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0478.html"/>
        <reference source="CESA" ref_id="CESA-2011:0478"/>
        <reference source="CVE" ref_id="CVE-2011-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1486.html"/>
        <description>libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which allows remote attackers to cause a denial of service (crash) by causing multiple threads to report errors at the same time.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:08.842-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:01.927-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:20.343-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libvirt-devel is earlier than 0:0.8.2-15.el5_6.4" test_ref="oval:org.mitre.oval:tst:97669"/>
          <criterion comment="libvirt is earlier than 0:0.8.2-15.el5_6.4" test_ref="oval:org.mitre.oval:tst:97813"/>
          <criterion comment="libvirt-python is earlier than 0:0.8.2-15.el5_6.4" test_ref="oval:org.mitre.oval:tst:97738"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21915" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:0257: subversion security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0257-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0257.html"/>
        <reference source="CESA" ref_id="CESA-2011:0257"/>
        <reference source="CVE" ref_id="CVE-2010-4539" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4539.html"/>
        <reference source="CVE" ref_id="CVE-2010-4644" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4644.html"/>
        <description>Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:11.110-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:01.814-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:20.199-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="subversion-devel is earlier than 0:1.6.11-7.el5_6.1" test_ref="oval:org.mitre.oval:tst:96996"/>
          <criterion comment="subversion is earlier than 0:1.6.11-7.el5_6.1" test_ref="oval:org.mitre.oval:tst:97345"/>
          <criterion comment="subversion-perl is earlier than 0:1.6.11-7.el5_6.1" test_ref="oval:org.mitre.oval:tst:97261"/>
          <criterion comment="subversion-ruby is earlier than 0:1.6.11-7.el5_6.1" test_ref="oval:org.mitre.oval:tst:97370"/>
          <criterion comment="subversion-javahl is earlier than 0:1.6.11-7.el5_6.1" test_ref="oval:org.mitre.oval:tst:97056"/>
          <criterion comment="mod_dav_svn is earlier than 0:1.6.11-7.el5_6.1" test_ref="oval:org.mitre.oval:tst:97424"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21913" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0918: curl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>curl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0918-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0918.html"/>
        <reference source="CVE" ref_id="CVE-2011-2192" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2192.html"/>
        <reference source="CESA-2011:0918" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-July/017641.html" ref_id="CESA-2011:0918-CentOS 5"/>
        <description>The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:50.782-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:01.735-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:20.090-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21913 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:34.392-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:19.065-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="curl-devel is earlier than 0:7.15.5-9.el5_6.3" test_ref="oval:org.mitre.oval:tst:137150"/>
            <criterion comment="curl is earlier than 0:7.15.5-9.el5_6.3" test_ref="oval:org.mitre.oval:tst:137724"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="curl is earlier than 0:7.19.7-26.el6_1.1" test_ref="oval:org.mitre.oval:tst:97809"/>
            <criterion comment="curl-debuginfo is earlier than 0:7.19.7-26.el6_1.1" test_ref="oval:org.mitre.oval:tst:137578"/>
            <criterion comment="libcurl is earlier than 0:7.19.7-26.el6_1.1" test_ref="oval:org.mitre.oval:tst:97421"/>
            <criterion comment="libcurl-devel is earlier than 0:7.19.7-26.el6_1.1" test_ref="oval:org.mitre.oval:tst:98175"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21912" version="42" class="patch">
      <metadata>
        <title>RHSA-2010:0062: bind security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0062-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0062.html"/>
        <reference source="CESA" ref_id="CESA-2010:0062"/>
        <reference source="CVE" ref_id="CVE-2010-0097" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0097.html"/>
        <reference source="CVE" ref_id="CVE-2010-0290" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0290.html"/>
        <reference source="CVE" ref_id="CVE-2010-0382" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0382.html"/>
        <description>ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta handles out-of-bailiwick data accompanying a secure response without re-fetching from the original source, which allows remote attackers to have an unspecified impact via a crafted response, aka Bug 20819.  NOTE: this vulnerability exists because of a regression during the fix for CVE-2009-4022.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:12.919-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:01.590-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:19.910-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="bind-utils is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:99074"/>
          <criterion comment="bind-devel is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:98963"/>
          <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:98390"/>
          <criterion comment="bind-chroot is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:98902"/>
          <criterion comment="bind-sdb is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:98737"/>
          <criterion comment="bind is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:99119"/>
          <criterion comment="bind-libs is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:99129"/>
          <criterion comment="caching-nameserver is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:98721"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21909" version="159" class="patch">
      <metadata>
        <title>RHSA-2011:0511: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0511-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0511.html"/>
        <reference source="CEBA" ref_id="CEBA-2011:0511"/>
        <reference source="CVE" ref_id="CVE-2011-0579" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0579.html"/>
        <reference source="CVE" ref_id="CVE-2011-0618" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0618.html"/>
        <reference source="CVE" ref_id="CVE-2011-0619" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0619.html"/>
        <reference source="CVE" ref_id="CVE-2011-0620" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0620.html"/>
        <reference source="CVE" ref_id="CVE-2011-0621" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0621.html"/>
        <reference source="CVE" ref_id="CVE-2011-0622" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0622.html"/>
        <reference source="CVE" ref_id="CVE-2011-0623" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0623.html"/>
        <reference source="CVE" ref_id="CVE-2011-0624" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0624.html"/>
        <reference source="CVE" ref_id="CVE-2011-0625" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0625.html"/>
        <reference source="CVE" ref_id="CVE-2011-0626" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0626.html"/>
        <reference source="CVE" ref_id="CVE-2011-0627" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0627.html"/>
        <reference source="CVE" ref_id="CVE-2011-0628" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0628.html"/>
        <description>Integer overflow in Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code via ActionScript that improperly handles a long array object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:21.709-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:00.813-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:18.878-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="flash-plugin is earlier than 0:10.3.181.14-1.el5" test_ref="oval:org.mitre.oval:tst:97214"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.3.181.14-1.el6" test_ref="oval:org.mitre.oval:tst:97384"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21907" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0292: java-1.4.2-ibm security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.4.2-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0292-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0292.html"/>
        <reference source="CVE" ref_id="CVE-2010-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4476.html"/>
        <description>The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:17.113-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:00.629-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:18.627-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.8-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:97464"/>
          <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.8-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:97269"/>
          <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.8-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:97270"/>
          <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.8-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:97427"/>
          <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.8-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:97472"/>
          <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.8-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:97530"/>
          <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.8-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:97380"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21906" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0376: dbus security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>dbus</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0376-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0376.html"/>
        <reference source="CESA" ref_id="CESA-2011:0376"/>
        <reference source="CVE" ref_id="CVE-2010-4352" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4352.html"/>
        <description>Stack consumption vulnerability in D-Bus (aka DBus) before 1.4.1 allows local users to cause a denial of service (daemon crash) via a message containing many nested variants.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:57.289-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:00.531-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:18.499-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dbus-devel is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:97463"/>
            <criterion comment="dbus is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:97598"/>
            <criterion comment="dbus-x11 is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:97339"/>
            <criterion comment="dbus-libs is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:97633"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dbus-devel is earlier than 1:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:97597"/>
            <criterion comment="dbus is earlier than 1:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:97533"/>
            <criterion comment="dbus-x11 is earlier than 1:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:97572"/>
            <criterion comment="dbus-libs is earlier than 1:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:97366"/>
            <criterion comment="dbus-doc is earlier than 1:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:96980"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21902" version="6" class="patch">
      <metadata>
        <title>RHSA-2014:0018: libXfont security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libXfont</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0018-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0018.html"/>
        <reference source="CESA" ref_id="CESA-2014:0018"/>
        <reference source="CVE" ref_id="CVE-2013-6462" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6462.html"/>
        <description>Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in a character name in a BDF font file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:58:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:42:31.548-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:00.143-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:17.954-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21902 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:37.127-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:41.396-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libXfont-devel is earlier than 0:1.2.2-1.0.5.el5_10" test_ref="oval:org.mitre.oval:tst:98673"/>
            <criterion comment="libXfont is earlier than 0:1.2.2-1.0.5.el5_10" test_ref="oval:org.mitre.oval:tst:98412"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libXfont-devel is earlier than 0:1.4.5-3.el6_5" test_ref="oval:org.mitre.oval:tst:99034"/>
            <criterion comment="libXfont is earlier than 0:1.4.5-3.el6_5" test_ref="oval:org.mitre.oval:tst:98834"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21901" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0392: libtiff security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0392-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0392.html"/>
        <reference source="CESA" ref_id="CESA-2011:0392"/>
        <reference source="CVE" ref_id="CVE-2011-1167" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1167.html"/>
        <description>Heap-based buffer overflow in the thunder (aka ThunderScan) decoder in tif_thunder.c in LibTIFF 3.9.4 and earlier allows remote attackers to execute arbitrary code via crafted THUNDER_2BITDELTAS data in a .tiff file that has an unexpected BitsPerSample value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:50.298-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:00.046-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:17.811-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libtiff is earlier than 0:3.8.2-7.el5_6.7" test_ref="oval:org.mitre.oval:tst:97237"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-7.el5_6.7" test_ref="oval:org.mitre.oval:tst:97664"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libtiff is earlier than 0:3.9.4-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:96686"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:96834"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:97547"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21900" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:0169: java-1.5.0-ibm security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0169-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0169.html"/>
        <reference source="CVE" ref_id="CVE-2010-3553" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3553.html"/>
        <reference source="CVE" ref_id="CVE-2010-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3557.html"/>
        <reference source="CVE" ref_id="CVE-2010-3571" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3571.html"/>
        <description>Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is an integer overflow in the color profile parser that allows remote attackers to execute arbitrary code via a crafted Tag structure in a color profile.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:27.146-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:59.895-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:17.632-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97095"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97146"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:96896"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:96911"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97121"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:96913"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97213"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97204"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:96819"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:96918"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:97086"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:97172"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:97247"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:97084"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:96683"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21899" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0843: postfix security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>postfix</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0843-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0843.html"/>
        <reference source="CVE" ref_id="CVE-2011-1720" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1720.html"/>
        <reference source="CESA-2011:0843" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-May/017595.html" ref_id="CESA-2011:0843-CentOS 5"/>
        <description>The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:11.824-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:59.834-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:17.528-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21899 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:32.261-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:18.771-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postfix is earlier than 2:2.3.3-2.3.el5_6" test_ref="oval:org.mitre.oval:tst:136888"/>
            <criterion comment="postfix-pflogsumm is earlier than 2:2.3.3-2.3.el5_6" test_ref="oval:org.mitre.oval:tst:137246"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postfix is earlier than 2:2.6.6-2.2.el6_1" test_ref="oval:org.mitre.oval:tst:97716"/>
            <criterion comment="postfix-debuginfo is earlier than 2:2.6.6-2.2.el6_1" test_ref="oval:org.mitre.oval:tst:137547"/>
            <criterion comment="postfix-perl-scripts is earlier than 2:2.6.6-2.2.el6_1" test_ref="oval:org.mitre.oval:tst:97683"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21898" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0305: samba security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0305-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0305.html"/>
        <reference source="CVE" ref_id="CVE-2011-0719" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0719.html"/>
        <reference source="CESA-2011:0305" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017389.html" ref_id="CESA-2011:0305-CentOS 5"/>
        <description>Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macro, which allows remote attackers to cause a denial of service (stack memory corruption, and infinite loop or daemon crash) by opening a large number of files, related to (1) Winbind or (2) smbd.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:07.959-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:59.749-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:17.413-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21898 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:22.833-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:18.350-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.29.el5_6.2" test_ref="oval:org.mitre.oval:tst:137684"/>
            <criterion comment="libsmbclient is earlier than 0:3.0.33-3.29.el5_6.2" test_ref="oval:org.mitre.oval:tst:137852"/>
            <criterion comment="samba is earlier than 0:3.0.33-3.29.el5_6.2" test_ref="oval:org.mitre.oval:tst:137854"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-3.29.el5_6.2" test_ref="oval:org.mitre.oval:tst:137175"/>
            <criterion comment="samba-common is earlier than 0:3.0.33-3.29.el5_6.2" test_ref="oval:org.mitre.oval:tst:137757"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-3.29.el5_6.2" test_ref="oval:org.mitre.oval:tst:137782"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libsmbclient is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97558"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97294"/>
            <criterion comment="samba is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97333"/>
            <criterion comment="samba-client is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97466"/>
            <criterion comment="samba-common is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97255"/>
            <criterion comment="samba-debuginfo is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:137366"/>
            <criterion comment="samba-doc is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97568"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97488"/>
            <criterion comment="samba-swat is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97542"/>
            <criterion comment="samba-winbind is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97325"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97507"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97567"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21896" version="198" class="patch">
      <metadata>
        <title>RHSA-2011:0927: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0927-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0927.html"/>
        <reference source="CESA" ref_id="CESA-2011:0927"/>
        <reference source="CVE" ref_id="CVE-2010-4649" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4649.html"/>
        <reference source="CVE" ref_id="CVE-2011-0695" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0695.html"/>
        <reference source="CVE" ref_id="CVE-2011-0711" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0711.html"/>
        <reference source="CVE" ref_id="CVE-2011-1044" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1044.html"/>
        <reference source="CVE" ref_id="CVE-2011-1182" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1182.html"/>
        <reference source="CVE" ref_id="CVE-2011-1573" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1573.html"/>
        <reference source="CVE" ref_id="CVE-2011-1576" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1576.html"/>
        <reference source="CVE" ref_id="CVE-2011-1593" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1593.html"/>
        <reference source="CVE" ref_id="CVE-2011-1745" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1745.html"/>
        <reference source="CVE" ref_id="CVE-2011-1746" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1746.html"/>
        <reference source="CVE" ref_id="CVE-2011-1776" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1776.html"/>
        <reference source="CVE" ref_id="CVE-2011-1936" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1936.html"/>
        <reference source="CVE" ref_id="CVE-2011-2022" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2022.html"/>
        <reference source="CVE" ref_id="CVE-2011-2213" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2213.html"/>
        <reference source="CVE" ref_id="CVE-2011-2492" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2492.html"/>
        <description>The bluetooth subsystem in the Linux kernel before 3.0-rc4 does not properly initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel memory via a crafted getsockopt system call, related to (1) the l2cap_sock_getsockopt_old function in net/bluetooth/l2cap_sock.c and (2) the rfcomm_sock_getsockopt_old function in net/bluetooth/rfcomm/sock.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:56.215-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:59.320-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:16.760-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:98249"/>
          <criterion comment="kernel is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:98200"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:97709"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:98217"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:98019"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:98283"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:98058"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:97784"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:98276"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:98071"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:98213"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:97611"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21893" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0102: flash-plugin security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0102-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0102.html"/>
        <reference source="CVE" ref_id="CVE-2010-0186" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0186.html"/>
        <reference source="CVE" ref_id="CVE-2010-0187" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0187.html"/>
        <description>Adobe Flash Player before 10.0.45.2 and Adobe AIR before 1.5.3.9130 allow remote attackers to cause a denial of service (application crash) via a modified SWF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:01.966-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:59.060-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:16.423-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="flash-plugin is earlier than 0:10.0.45.2-1.el5" test_ref="oval:org.mitre.oval:tst:99198"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21890" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1019: libvirt security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1019-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1019.html"/>
        <reference source="CESA" ref_id="CESA-2011:1019"/>
        <reference source="CVE" ref_id="CVE-2011-2511" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2511.html"/>
        <description>Integer overflow in libvirt before 0.9.3 allows remote authenticated users to cause a denial of service (libvirtd crash) and possibly execute arbitrary code via a crafted VirDomainGetVcpus RPC call that triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:14.447-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:58.756-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:16.007-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libvirt-devel is earlier than 0:0.8.2-22.el5" test_ref="oval:org.mitre.oval:tst:98265"/>
          <criterion comment="libvirt is earlier than 0:0.8.2-22.el5" test_ref="oval:org.mitre.oval:tst:97868"/>
          <criterion comment="libvirt-python is earlier than 0:0.8.2-22.el5" test_ref="oval:org.mitre.oval:tst:97819"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21886" version="42" class="patch">
      <metadata>
        <title>RHSA-2010:0115: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0115-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0115.html"/>
        <reference source="CESA" ref_id="CESA-2010:0115"/>
        <reference source="CVE" ref_id="CVE-2010-0277" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0277.html"/>
        <reference source="CVE" ref_id="CVE-2010-0420" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0420.html"/>
        <reference source="CVE" ref_id="CVE-2010-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0423.html"/>
        <description>gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:16.823-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:58.389-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:15.624-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libpurple-perl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:98516"/>
          <criterion comment="finch is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:99156"/>
          <criterion comment="libpurple is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:99107"/>
          <criterion comment="pidgin is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:99199"/>
          <criterion comment="libpurple-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:99241"/>
          <criterion comment="finch-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:98889"/>
          <criterion comment="pidgin-perl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:98487"/>
          <criterion comment="pidgin-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:99166"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:99246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21885" version="198" class="patch">
      <metadata>
        <title>RHSA-2011:1386: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1386-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1386.html"/>
        <reference source="CESA" ref_id="CESA-2011:1386"/>
        <reference source="CVE" ref_id="CVE-2009-4067" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4067.html"/>
        <reference source="CVE" ref_id="CVE-2011-1160" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1160.html"/>
        <reference source="CVE" ref_id="CVE-2011-1585" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1585.html"/>
        <reference source="CVE" ref_id="CVE-2011-1833" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1833.html"/>
        <reference source="CVE" ref_id="CVE-2011-2484" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2484.html"/>
        <reference source="CVE" ref_id="CVE-2011-2496" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2496.html"/>
        <reference source="CVE" ref_id="CVE-2011-2695" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2695.html"/>
        <reference source="CVE" ref_id="CVE-2011-2699" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2699.html"/>
        <reference source="CVE" ref_id="CVE-2011-2723" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2723.html"/>
        <reference source="CVE" ref_id="CVE-2011-2942" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2942.html"/>
        <reference source="CVE" ref_id="CVE-2011-3131" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3131.html"/>
        <reference source="CVE" ref_id="CVE-2011-3188" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3188.html"/>
        <reference source="CVE" ref_id="CVE-2011-3191" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3191.html"/>
        <reference source="CVE" ref_id="CVE-2011-3209" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3209.html"/>
        <reference source="CVE" ref_id="CVE-2011-3347" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3347.html"/>
        <description>A certain Red Hat patch to the be2net implementation in the kernel package before 2.6.32-218.el6 on Red Hat Enterprise Linux (RHEL) 6, when promiscuous mode is enabled, allows remote attackers to cause a denial of service (system crash) via non-member VLAN packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:09.671-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:57.934-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:15.238-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:98575"/>
          <criterion comment="kernel is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:98715"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:98641"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:98714"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:98652"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:97930"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:98057"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:98342"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:98639"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:98685"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:98543"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:98643"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21884" version="81" class="patch">
      <metadata>
        <title>RHSA-2011:1164: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1164-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1164.html"/>
        <reference source="CESA" ref_id="CESA-2011:1164"/>
        <reference source="CVE" ref_id="CVE-2011-0084" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0084.html"/>
        <reference source="CVE" ref_id="CVE-2011-2378" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2378.html"/>
        <reference source="CVE" ref_id="CVE-2011-2981" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2981.html"/>
        <reference source="CVE" ref_id="CVE-2011-2982" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2982.html"/>
        <reference source="CVE" ref_id="CVE-2011-2983" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2983.html"/>
        <reference source="CVE" ref_id="CVE-2011-2984" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2984.html"/>
        <description>Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a tab element, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by establishing a content area and registering for drop events.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:09.699-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:57.693-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:15.035-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.20-2.el5" test_ref="oval:org.mitre.oval:tst:98356"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.20-2.el5" test_ref="oval:org.mitre.oval:tst:97400"/>
            <criterion comment="firefox is earlier than 0:3.6.20-2.el5" test_ref="oval:org.mitre.oval:tst:98011"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.20-2.el6_1" test_ref="oval:org.mitre.oval:tst:98376"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.20-2.el6_1" test_ref="oval:org.mitre.oval:tst:98396"/>
            <criterion comment="firefox is earlier than 0:3.6.20-2.el6_1" test_ref="oval:org.mitre.oval:tst:98239"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21877" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0164: openssl097a security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openssl097a</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0164-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0164.html"/>
        <reference source="CESA" ref_id="CESA-2010:0164"/>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html"/>
        <description>The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:25.530-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:57.344-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:14.640-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="openssl097a is earlier than 0:0.9.7a-9.el5_4.2" test_ref="oval:org.mitre.oval:tst:98782"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21876" version="55" class="patch">
      <metadata>
        <title>RHSA-2011:1220: samba3x security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>samba3x</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1220-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1220.html"/>
        <reference source="CESA" ref_id="CESA-2011:1220"/>
        <reference source="CVE" ref_id="CVE-2011-1678" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1678.html"/>
        <reference source="CVE" ref_id="CVE-2011-2522" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2522.html"/>
        <reference source="CVE" ref_id="CVE-2011-2694" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2694.html"/>
        <reference source="CVE" ref_id="CVE-2011-2724" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2724.html"/>
        <description>The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3.5.10 and earlier does not properly verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0547.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:31.359-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:57.181-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:14.466-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="samba3x-swat is earlier than 0:3.5.4-0.83.el5_7.2" test_ref="oval:org.mitre.oval:tst:98171"/>
          <criterion comment="samba3x-client is earlier than 0:3.5.4-0.83.el5_7.2" test_ref="oval:org.mitre.oval:tst:98327"/>
          <criterion comment="samba3x-doc is earlier than 0:3.5.4-0.83.el5_7.2" test_ref="oval:org.mitre.oval:tst:97607"/>
          <criterion comment="samba3x-winbind is earlier than 0:3.5.4-0.83.el5_7.2" test_ref="oval:org.mitre.oval:tst:98463"/>
          <criterion comment="samba3x is earlier than 0:3.5.4-0.83.el5_7.2" test_ref="oval:org.mitre.oval:tst:98275"/>
          <criterion comment="samba3x-winbind-devel is earlier than 0:3.5.4-0.83.el5_7.2" test_ref="oval:org.mitre.oval:tst:98067"/>
          <criterion comment="samba3x-common is earlier than 0:3.5.4-0.83.el5_7.2" test_ref="oval:org.mitre.oval:tst:98160"/>
          <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.5.4-0.83.el5_7.2" test_ref="oval:org.mitre.oval:tst:98311"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21873" version="81" class="patch">
      <metadata>
        <title>RHSA-2011:0412: glibc security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0412-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0412.html"/>
        <reference source="CESA" ref_id="CESA-2011:0412"/>
        <reference source="CVE" ref_id="CVE-2010-0296" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0296.html"/>
        <reference source="CVE" ref_id="CVE-2011-0536" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0536.html"/>
        <reference source="CVE" ref_id="CVE-2011-1071" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1071.html"/>
        <reference source="CVE" ref_id="CVE-2011-1095" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1095.html"/>
        <reference source="CVE" ref_id="CVE-2011-1658" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1658.html"/>
        <reference source="CVE" ref_id="CVE-2011-1659" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1659.html"/>
        <description>Integer overflow in posix/fnmatch.c in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long UTF8 string that is used in an fnmatch call with a crafted pattern argument, a different vulnerability than CVE-2011-1071.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:02.692-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:49.095-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:13.966-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="glibc-common is earlier than 0:2.5-58.el5_6.2" test_ref="oval:org.mitre.oval:tst:97278"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-58.el5_6.2" test_ref="oval:org.mitre.oval:tst:96986"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-58.el5_6.2" test_ref="oval:org.mitre.oval:tst:97665"/>
          <criterion comment="glibc is earlier than 0:2.5-58.el5_6.2" test_ref="oval:org.mitre.oval:tst:97008"/>
          <criterion comment="nscd is earlier than 0:2.5-58.el5_6.2" test_ref="oval:org.mitre.oval:tst:96920"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-58.el5_6.2" test_ref="oval:org.mitre.oval:tst:97720"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21865" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0346: openldap security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openldap</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0346-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0346.html"/>
        <reference source="CESA" ref_id="CESA-2011:0346"/>
        <reference source="CVE" ref_id="CVE-2011-1024" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1024.html"/>
        <description>chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:44.092-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:48.149-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:13.134-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openldap-devel is earlier than 0:2.3.43-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:97128"/>
          <criterion comment="openldap-clients is earlier than 0:2.3.43-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:97436"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.3.43-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:96625"/>
          <criterion comment="compat-openldap is earlier than 0:2.3.43_2.2.29-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:96740"/>
          <criterion comment="openldap is earlier than 0:2.3.43-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:97217"/>
          <criterion comment="openldap-servers is earlier than 0:2.3.43-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:97594"/>
          <criterion comment="openldap-servers-overlays is earlier than 0:2.3.43-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:97407"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21862" version="81" class="patch">
      <metadata>
        <title>RHSA-2010:0147: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0147-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0147.html"/>
        <reference source="CESA" ref_id="CESA-2010:0147"/>
        <reference source="CVE" ref_id="CVE-2009-4308" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4308.html"/>
        <reference source="CVE" ref_id="CVE-2010-0003" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0003.html"/>
        <reference source="CVE" ref_id="CVE-2010-0007" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0007.html"/>
        <reference source="CVE" ref_id="CVE-2010-0008" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0008.html"/>
        <reference source="CVE" ref_id="CVE-2010-0415" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0415.html"/>
        <reference source="CVE" ref_id="CVE-2010-0437" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0437.html"/>
        <description>The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle certain circumstances involving an IPv6 TUN network interface and a large number of neighbors, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:46.257-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:47.834-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:12.877-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:99232"/>
          <criterion comment="kernel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:99234"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:98981"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:99251"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:99280"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:98432"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:98401"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:99173"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:99116"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:98949"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:98966"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:98924"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21859" version="250" class="patch">
      <metadata>
        <title>RHSA-2011:0282: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0282-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0282.html"/>
        <reference source="CVE" ref_id="CVE-2010-4422" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4422.html"/>
        <reference source="CVE" ref_id="CVE-2010-4447" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4447.html"/>
        <reference source="CVE" ref_id="CVE-2010-4448" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4448.html"/>
        <reference source="CVE" ref_id="CVE-2010-4450" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4450.html"/>
        <reference source="CVE" ref_id="CVE-2010-4451" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4451.html"/>
        <reference source="CVE" ref_id="CVE-2010-4452" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4452.html"/>
        <reference source="CVE" ref_id="CVE-2010-4454" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4454.html"/>
        <reference source="CVE" ref_id="CVE-2010-4462" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4462.html"/>
        <reference source="CVE" ref_id="CVE-2010-4463" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4463.html"/>
        <reference source="CVE" ref_id="CVE-2010-4465" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4465.html"/>
        <reference source="CVE" ref_id="CVE-2010-4466" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4466.html"/>
        <reference source="CVE" ref_id="CVE-2010-4467" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4467.html"/>
        <reference source="CVE" ref_id="CVE-2010-4468" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4468.html"/>
        <reference source="CVE" ref_id="CVE-2010-4469" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4469.html"/>
        <reference source="CVE" ref_id="CVE-2010-4470" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4470.html"/>
        <reference source="CVE" ref_id="CVE-2010-4471" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4471.html"/>
        <reference source="CVE" ref_id="CVE-2010-4472" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4472.html"/>
        <reference source="CVE" ref_id="CVE-2010-4473" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4473.html"/>
        <reference source="CVE" ref_id="CVE-2010-4475" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4475.html"/>
        <reference source="CVE" ref_id="CVE-2010-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4476.html"/>
        <description>The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:39.073-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:47.194-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:12.216-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97528"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:96905"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97515"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97502"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97418"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97508"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97282"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97161"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97346"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97482"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97455"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97392"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21857" version="174" class="patch">
      <metadata>
        <title>RHSA-2011:0206: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0206-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0206.html"/>
        <reference source="CVE" ref_id="CVE-2011-0558" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0558.html"/>
        <reference source="CVE" ref_id="CVE-2011-0559" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0559.html"/>
        <reference source="CVE" ref_id="CVE-2011-0560" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0560.html"/>
        <reference source="CVE" ref_id="CVE-2011-0561" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0561.html"/>
        <reference source="CVE" ref_id="CVE-2011-0571" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0571.html"/>
        <reference source="CVE" ref_id="CVE-2011-0572" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0572.html"/>
        <reference source="CVE" ref_id="CVE-2011-0573" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0573.html"/>
        <reference source="CVE" ref_id="CVE-2011-0574" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0574.html"/>
        <reference source="CVE" ref_id="CVE-2011-0575" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0575.html"/>
        <reference source="CVE" ref_id="CVE-2011-0577" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0577.html"/>
        <reference source="CVE" ref_id="CVE-2011-0578" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0578.html"/>
        <reference source="CVE" ref_id="CVE-2011-0607" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0607.html"/>
        <reference source="CVE" ref_id="CVE-2011-0608" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0608.html"/>
        <description>Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0559, CVE-2011-0560, CVE-2011-0561, CVE-2011-0571, CVE-2011-0572, CVE-2011-0573, CVE-2011-0574, CVE-2011-0578, and CVE-2011-0607.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:49.193-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:46.739-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:11.869-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21857 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:14.236-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:17.123-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.2.152.27-1.el5" test_ref="oval:org.mitre.oval:tst:137764"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:10.2.152.27-1.el6" test_ref="oval:org.mitre.oval:tst:97503"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21856" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0337: vsftpd security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>vsftpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0337-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0337.html"/>
        <reference source="CVE" ref_id="CVE-2011-0762" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0762.html"/>
        <reference source="CESA-2011:0337" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017401.html" ref_id="CESA-2011:0337-CentOS 5"/>
        <description>The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:16.639-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:46.661-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:11.779-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21856 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:23.068-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:16.825-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="vsftpd is earlier than 0:2.0.5-16.el5_6.1" test_ref="oval:org.mitre.oval:tst:137483"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="vsftpd is earlier than 0:2.2.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97416"/>
            <criterion comment="vsftpd-debuginfo is earlier than 0:2.2.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:137665"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21850" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0170: libuser security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libuser</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0170-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0170.html"/>
        <reference source="CESA" ref_id="CESA-2011:0170"/>
        <reference source="CVE" ref_id="CVE-2011-0002" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0002.html"/>
        <description>libuser before 0.57 uses a cleartext password value of (1) !! or (2) x for new LDAP user accounts, which makes it easier for remote attackers to obtain access by specifying one of these values.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:22.827-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:46.558-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:11.681-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libuser-devel is earlier than 0:0.54.7-2.1.el5_5.2" test_ref="oval:org.mitre.oval:tst:97085"/>
            <criterion comment="libuser is earlier than 0:0.54.7-2.1.el5_5.2" test_ref="oval:org.mitre.oval:tst:96455"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libuser-devel is earlier than 0:0.56.13-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:97036"/>
            <criterion comment="libuser is earlier than 0:0.56.13-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:97221"/>
            <criterion comment="libuser-python is earlier than 0:0.56.13-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:97120"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21842" version="52" class="patch">
      <metadata>
        <title>RHSA-2011:1241: ecryptfs-utils security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>ecryptfs-utils</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1241-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1241.html"/>
        <reference source="CESA" ref_id="CESA-2011:1241"/>
        <reference source="CVE" ref_id="CVE-2011-1831" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1831.html"/>
        <reference source="CVE" ref_id="CVE-2011-1832" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1832.html"/>
        <reference source="CVE" ref_id="CVE-2011-1834" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1834.html"/>
        <reference source="CVE" ref_id="CVE-2011-1835" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1835.html"/>
        <reference source="CVE" ref_id="CVE-2011-1837" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1837.html"/>
        <reference source="CVE" ref_id="CVE-2011-3145" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3145.html"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:38.464-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:46.099-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:11.009-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="ecryptfs-utils-gui is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:97689"/>
            <criterion comment="ecryptfs-utils is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:98180"/>
            <criterion comment="ecryptfs-utils-devel is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:98129"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="ecryptfs-utils-python is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:98418"/>
            <criterion comment="ecryptfs-utils is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:97518"/>
            <criterion comment="ecryptfs-utils-devel is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:97673"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21834" version="42" class="patch">
      <metadata>
        <title>RHSA-2010:0627: kvm security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0627-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0627.html"/>
        <reference source="CESA" ref_id="CESA-2010:0627"/>
        <reference source="CVE" ref_id="CVE-2010-0431" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0431.html"/>
        <reference source="CVE" ref_id="CVE-2010-0435" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0435.html"/>
        <reference source="CVE" ref_id="CVE-2010-2784" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2784.html"/>
        <description>The subpage MMIO initialization functionality in the subpage_register function in exec.c in QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly select the index for access to the callback array, which allows guest OS users to cause a denial of service (guest OS crash) or possibly gain privileges via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:49.822-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:45.932-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:10.855-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kvm-qemu-img is earlier than 0:83-164.el5_5.21" test_ref="oval:org.mitre.oval:tst:99690"/>
          <criterion comment="kvm is earlier than 0:83-164.el5_5.21" test_ref="oval:org.mitre.oval:tst:99630"/>
          <criterion comment="kmod-kvm is earlier than 0:83-164.el5_5.21" test_ref="oval:org.mitre.oval:tst:99621"/>
          <criterion comment="kvm-tools is earlier than 0:83-164.el5_5.21" test_ref="oval:org.mitre.oval:tst:99624"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21828" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0166: gnutls security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0166-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0166.html"/>
        <reference source="CESA" ref_id="CESA-2010:0166"/>
        <reference source="CVE" ref_id="CVE-2009-2409" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2409.html"/>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html"/>
        <description>The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:18.168-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:45.823-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:10.745-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="gnutls-devel is earlier than 0:1.4.1-3.el5_4.8" test_ref="oval:org.mitre.oval:tst:99055"/>
          <criterion comment="gnutls-utils is earlier than 0:1.4.1-3.el5_4.8" test_ref="oval:org.mitre.oval:tst:99279"/>
          <criterion comment="gnutls is earlier than 0:1.4.1-3.el5_4.8" test_ref="oval:org.mitre.oval:tst:99070"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21827" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0198: postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>postgresql84</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0198-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0198.html"/>
        <reference source="CESA" ref_id="CESA-2011:0198"/>
        <reference source="CVE" ref_id="CVE-2010-4015" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4015.html"/>
        <description>Buffer overflow in the gettoken function in contrib/intarray/_int_bool.c in the intarray array module in PostgreSQL 9.0.x before 9.0.3, 8.4.x before 8.4.7, 8.3.x before 8.3.14, and 8.2.x before 8.2.20 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via integers with a large number of digits to unspecified functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:57.713-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:45.720-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:10.635-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="postgresql84-tcl is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97419"/>
          <criterion comment="postgresql84-docs is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97256"/>
          <criterion comment="postgresql84-python is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97254"/>
          <criterion comment="postgresql84-plpython is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97378"/>
          <criterion comment="postgresql84-libs is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97260"/>
          <criterion comment="postgresql84-test is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97257"/>
          <criterion comment="postgresql84-server is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97374"/>
          <criterion comment="postgresql84-plperl is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:96445"/>
          <criterion comment="postgresql84-pltcl is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97034"/>
          <criterion comment="postgresql84-devel is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97241"/>
          <criterion comment="postgresql84 is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:96811"/>
          <criterion comment="postgresql84-contrib is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:96776"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21825" version="55" class="patch">
      <metadata>
        <title>RHSA-2011:0303: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0303-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0303.html"/>
        <reference source="CESA" ref_id="CESA-2011:0303"/>
        <reference source="CVE" ref_id="CVE-2010-4249" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4249.html"/>
        <reference source="CVE" ref_id="CVE-2010-4251" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4251.html"/>
        <reference source="CVE" ref_id="CVE-2010-4655" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4655.html"/>
        <reference source="CVE" ref_id="CVE-2010-4805" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4805.html"/>
        <description>The socket implementation in net/core/sock.c in the Linux kernel before 2.6.35 does not properly manage a backlog of received packets, which allows remote attackers to cause a denial of service by sending a large amount of network traffic, related to the sk_add_backlog function and the sk_rmem_alloc socket field.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4251.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:01.432-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:45.527-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:10.445-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-238.5.1.el5" test_ref="oval:org.mitre.oval:tst:97447"/>
          <criterion comment="kernel is earlier than 0:2.6.18-238.5.1.el5" test_ref="oval:org.mitre.oval:tst:97397"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-238.5.1.el5" test_ref="oval:org.mitre.oval:tst:96702"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-238.5.1.el5" test_ref="oval:org.mitre.oval:tst:97543"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-238.5.1.el5" test_ref="oval:org.mitre.oval:tst:97196"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-238.5.1.el5" test_ref="oval:org.mitre.oval:tst:97243"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-238.5.1.el5" test_ref="oval:org.mitre.oval:tst:97258"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-238.5.1.el5" test_ref="oval:org.mitre.oval:tst:97352"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-238.5.1.el5" test_ref="oval:org.mitre.oval:tst:96981"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-238.5.1.el5" test_ref="oval:org.mitre.oval:tst:96925"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-238.5.1.el5" test_ref="oval:org.mitre.oval:tst:97559"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-238.5.1.el5" test_ref="oval:org.mitre.oval:tst:97552"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21822" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0324: logwatch security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>logwatch</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0324-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0324.html"/>
        <reference source="CVE" ref_id="CVE-2011-1018" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1018.html"/>
        <reference source="CESA-2011:0324" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017365.html" ref_id="CESA-2011:0324-CentOS 5"/>
        <description>logwatch.pl in Logwatch 7.3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in a log file name, as demonstrated via a crafted username to a Samba server.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:02.872-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:45.442-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:10.336-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21822 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:14.464-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:16.298-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="logwatch is earlier than 0:7.3-9.el5_6" test_ref="oval:org.mitre.oval:tst:137653"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="logwatch is earlier than 0:7.3.6-49.el6" test_ref="oval:org.mitre.oval:tst:97039"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21816" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:0312: thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0312-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0312.html"/>
        <reference source="CVE" ref_id="CVE-2011-0051" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0051.html"/>
        <reference source="CVE" ref_id="CVE-2011-0053" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0053.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:30.981-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:45.224-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:10.061-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-14.el5_6" test_ref="oval:org.mitre.oval:tst:97322"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21815" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0018: dbus security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>dbus</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0018-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0018.html"/>
        <reference source="CESA" ref_id="CESA-2010:0018"/>
        <reference source="CVE" ref_id="CVE-2009-1189" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1189.html"/>
        <description>The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key.  NOTE: this is due to an incorrect fix for CVE-2008-3834.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:21.983-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:45.128-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:09.937-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="dbus-x11 is earlier than 0:1.1.2-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:98880"/>
          <criterion comment="dbus-devel is earlier than 0:1.1.2-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:98919"/>
          <criterion comment="dbus is earlier than 0:1.1.2-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:99069"/>
          <criterion comment="dbus-libs is earlier than 0:1.1.2-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:98923"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21814" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:0199: krb5 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0199-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0199.html"/>
        <reference source="CESA" ref_id="CESA-2011:0199"/>
        <reference source="CVE" ref_id="CVE-2011-0281" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0281.html"/>
        <reference source="CVE" ref_id="CVE-2011-0282" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0282.html"/>
        <description>The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (NULL pointer dereference or buffer over-read, and daemon crash) via a crafted principal name.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:49.382-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:45.011-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:09.794-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="krb5-libs is earlier than 0:1.6.1-55.el5_6.1" test_ref="oval:org.mitre.oval:tst:97355"/>
          <criterion comment="krb5-devel is earlier than 0:1.6.1-55.el5_6.1" test_ref="oval:org.mitre.oval:tst:96527"/>
          <criterion comment="krb5-server is earlier than 0:1.6.1-55.el5_6.1" test_ref="oval:org.mitre.oval:tst:97428"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.6.1-55.el5_6.1" test_ref="oval:org.mitre.oval:tst:97265"/>
          <criterion comment="krb5 is earlier than 0:1.6.1-55.el5_6.1" test_ref="oval:org.mitre.oval:tst:97405"/>
          <criterion comment="krb5-workstation is earlier than 0:1.6.1-55.el5_6.1" test_ref="oval:org.mitre.oval:tst:97369"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21813" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0154: hplip security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>hplip</product>
          <product>hplip3</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0154-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0154.html"/>
        <reference source="CVE" ref_id="CVE-2010-4267" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4267.html"/>
        <reference source="CESA-2011:0154" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017342.html" ref_id="CESA-2011:0154-CentOS 5"/>
        <description>Stack-based buffer overflow in the hpmud_get_pml function in io/hpmud/pml.c in Hewlett-Packard Linux Imaging and Printing (HPLIP) 1.6.7, 3.9.8, 3.10.9, and probably other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SNMP response with a large length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:52.876-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:44.918-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:09.690-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21813 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:30.525-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:15.635-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="hpijs is earlier than 0:1.6.7-6.el5_6.1" test_ref="oval:org.mitre.oval:tst:137298"/>
            <criterion comment="hpijs3 is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:137888"/>
            <criterion comment="hplip is earlier than 0:1.6.7-6.el5_6.1" test_ref="oval:org.mitre.oval:tst:137564"/>
            <criterion comment="hplip3 is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:137308"/>
            <criterion comment="hplip3-common is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:136965"/>
            <criterion comment="hplip3-gui is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:137608"/>
            <criterion comment="hplip3-libs is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:137659"/>
            <criterion comment="libsane-hpaio is earlier than 0:1.6.7-6.el5_6.1" test_ref="oval:org.mitre.oval:tst:137858"/>
            <criterion comment="libsane-hpaio3 is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:137631"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="hpijs is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:96882"/>
            <criterion comment="hplip is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:96224"/>
            <criterion comment="hplip-common is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:96578"/>
            <criterion comment="hplip-debuginfo is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:137565"/>
            <criterion comment="hplip-gui is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:97154"/>
            <criterion comment="hplip-libs is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:97133"/>
            <criterion comment="libsane-hpaio is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:97130"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21809" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0291: java-1.5.0-ibm security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0291-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0291.html"/>
        <reference source="CVE" ref_id="CVE-2010-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4476.html"/>
        <description>The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:53.700-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:44.728-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:09.474-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97468"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97268"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97487"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97201"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97560"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97385"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97432"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97272"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:97273"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:97207"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:97561"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:97544"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:97460"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:96815"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:97361"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21805" version="68" class="patch">
      <metadata>
        <title>RHSA-2010:0398: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0398-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0398.html"/>
        <reference source="CESA" ref_id="CESA-2010:0398"/>
        <reference source="CVE" ref_id="CVE-2010-0307" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0307.html"/>
        <reference source="CVE" ref_id="CVE-2010-0410" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0410.html"/>
        <reference source="CVE" ref_id="CVE-2010-0730" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0730.html"/>
        <reference source="CVE" ref_id="CVE-2010-1085" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1085.html"/>
        <reference source="CVE" ref_id="CVE-2010-1086" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1086.html"/>
        <description>The ULE decapsulation functionality in drivers/media/dvb/dvb-core/dvb_net.c in dvb-core in Linux kernel 2.6.33 and earlier allows attackers to cause a denial of service (infinite loop) via a crafted MPEG2-TS frame, related to an invalid Payload Pointer ULE.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:19.696-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:44.511-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:09.209-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.3.1.el5" test_ref="oval:org.mitre.oval:tst:98915"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.3.1.el5" test_ref="oval:org.mitre.oval:tst:99204"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.3.1.el5" test_ref="oval:org.mitre.oval:tst:99318"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.3.1.el5" test_ref="oval:org.mitre.oval:tst:99426"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.3.1.el5" test_ref="oval:org.mitre.oval:tst:99442"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.3.1.el5" test_ref="oval:org.mitre.oval:tst:99132"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.3.1.el5" test_ref="oval:org.mitre.oval:tst:99196"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.3.1.el5" test_ref="oval:org.mitre.oval:tst:98969"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.3.1.el5" test_ref="oval:org.mitre.oval:tst:98733"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.3.1.el5" test_ref="oval:org.mitre.oval:tst:99223"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.3.1.el5" test_ref="oval:org.mitre.oval:tst:99371"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.3.1.el5" test_ref="oval:org.mitre.oval:tst:98973"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21804" version="185" class="patch">
      <metadata>
        <title>RHSA-2010:0786: java-1.4.2-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.4.2-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0786-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0786.html"/>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html"/>
        <reference source="CVE" ref_id="CVE-2010-3541" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3541.html"/>
        <reference source="CVE" ref_id="CVE-2010-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3548.html"/>
        <reference source="CVE" ref_id="CVE-2010-3549" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3549.html"/>
        <reference source="CVE" ref_id="CVE-2010-3551" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3551.html"/>
        <reference source="CVE" ref_id="CVE-2010-3553" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3553.html"/>
        <reference source="CVE" ref_id="CVE-2010-3556" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3556.html"/>
        <reference source="CVE" ref_id="CVE-2010-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3557.html"/>
        <reference source="CVE" ref_id="CVE-2010-3562" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3562.html"/>
        <reference source="CVE" ref_id="CVE-2010-3565" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3565.html"/>
        <reference source="CVE" ref_id="CVE-2010-3568" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3568.html"/>
        <reference source="CVE" ref_id="CVE-2010-3569" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3569.html"/>
        <reference source="CVE" ref_id="CVE-2010-3571" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3571.html"/>
        <reference source="CVE" ref_id="CVE-2010-3572" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3572.html"/>
        <description>Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:47.221-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:44.113-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:08.793-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.6-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:99281"/>
          <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.6-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:99637"/>
          <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.6-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:99561"/>
          <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.6-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:99733"/>
          <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.6-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:99395"/>
          <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.6-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:99692"/>
          <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.6-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:99475"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21799" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0198: openldap security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>openldap</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0198-04" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0198.html"/>
        <reference source="CVE" ref_id="CVE-2009-3767" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3767.html"/>
        <description>libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:49.545-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:44.020-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:08.697-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openldap-devel is earlier than 0:2.3.43-12.el5" test_ref="oval:org.mitre.oval:tst:99037"/>
          <criterion comment="openldap-clients is earlier than 0:2.3.43-12.el5" test_ref="oval:org.mitre.oval:tst:98956"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.3.43-12.el5" test_ref="oval:org.mitre.oval:tst:98985"/>
          <criterion comment="compat-openldap is earlier than 0:2.3.43_2.2.29-12.el5" test_ref="oval:org.mitre.oval:tst:99202"/>
          <criterion comment="openldap is earlier than 0:2.3.43-12.el5" test_ref="oval:org.mitre.oval:tst:98867"/>
          <criterion comment="openldap-servers is earlier than 0:2.3.43-12.el5" test_ref="oval:org.mitre.oval:tst:99243"/>
          <criterion comment="openldap-servers-overlays is earlier than 0:2.3.43-12.el5" test_ref="oval:org.mitre.oval:tst:99172"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21795" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0054: openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0054-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0054.html"/>
        <reference source="CESA" ref_id="CESA-2010:0054"/>
        <reference source="CVE" ref_id="CVE-2009-2409" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2409.html"/>
        <reference source="CVE" ref_id="CVE-2009-4355" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4355.html"/>
        <description>Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:37.878-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:43.906-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:08.572-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openssl is earlier than 0:0.9.8e-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:98454"/>
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:99155"/>
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:98506"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21791" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1377: postgresql security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1377-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1377.html"/>
        <reference source="CESA" ref_id="CESA-2011:1377"/>
        <reference source="CVE" ref_id="CVE-2011-2483" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2483.html"/>
        <description>crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext password by leveraging knowledge of a password hash.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:03.572-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:43.725-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:08.374-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:98070"/>
            <criterion comment="postgresql-tcl is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:98409"/>
            <criterion comment="postgresql-server is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:97960"/>
            <criterion comment="postgresql-devel is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:98583"/>
            <criterion comment="postgresql-libs is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:98369"/>
            <criterion comment="postgresql-pl is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:98422"/>
            <criterion comment="postgresql-docs is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:98593"/>
            <criterion comment="postgresql-test is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:98172"/>
            <criterion comment="postgresql-python is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:98231"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:98173"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98538"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98349"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98004"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98411"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98566"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98607"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98510"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98655"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:97945"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98287"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21784" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1378: postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>postgresql84</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1378-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1378.html"/>
        <reference source="CESA" ref_id="CESA-2011:1378"/>
        <reference source="CVE" ref_id="CVE-2011-2483" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2483.html"/>
        <description>crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext password by leveraging knowledge of a password hash.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:27.786-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:43.408-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:07.986-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="postgresql84-tcl is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98611"/>
          <criterion comment="postgresql84-docs is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98452"/>
          <criterion comment="postgresql84-python is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98230"/>
          <criterion comment="postgresql84-plpython is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98631"/>
          <criterion comment="postgresql84-test is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98419"/>
          <criterion comment="postgresql84-server is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98473"/>
          <criterion comment="postgresql84-libs is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98494"/>
          <criterion comment="postgresql84-plperl is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98640"/>
          <criterion comment="postgresql84-pltcl is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98489"/>
          <criterion comment="postgresql84-devel is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98539"/>
          <criterion comment="postgresql84 is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:97948"/>
          <criterion comment="postgresql84-contrib is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98069"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21781" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0651: spice-xpi security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>spice-xpi</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0651-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0651.html"/>
        <reference source="CESA" ref_id="CESA-2010:0651"/>
        <reference source="CVE" ref_id="CVE-2010-2792" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2792.html"/>
        <reference source="CVE" ref_id="CVE-2010-2794" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2794.html"/>
        <description>The SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to overwrite arbitrary files via a symlink attack on an unspecified log file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:46.967-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:43.301-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:07.847-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="spice-xpi is earlier than 0:2.2-2.3.el5_5" test_ref="oval:org.mitre.oval:tst:99462"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21777" version="146" class="patch">
      <metadata>
        <title>RHSA-2010:0046: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0046-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0046.html"/>
        <reference source="CESA" ref_id="CESA-2010:0046"/>
        <reference source="CVE" ref_id="CVE-2006-6304" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6304.html"/>
        <reference source="CVE" ref_id="CVE-2009-2910" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2910.html"/>
        <reference source="CVE" ref_id="CVE-2009-3080" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3080.html"/>
        <reference source="CVE" ref_id="CVE-2009-3556" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3556.html"/>
        <reference source="CVE" ref_id="CVE-2009-3889" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3889.html"/>
        <reference source="CVE" ref_id="CVE-2009-3939" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3939.html"/>
        <reference source="CVE" ref_id="CVE-2009-4020" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4020.html"/>
        <reference source="CVE" ref_id="CVE-2009-4021" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4021.html"/>
        <reference source="CVE" ref_id="CVE-2009-4138" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4138.html"/>
        <reference source="CVE" ref_id="CVE-2009-4141" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4141.html"/>
        <reference source="CVE" ref_id="CVE-2009-4272" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4272.html"/>
        <description>A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to cause a denial of service (deadlock) via crafted packets that force collisions in the IPv4 routing hash table, and trigger a routing "emergency" in which a hash chain is too long.  NOTE: this is related to an issue in the Linux kernel before 2.6.31, when the kernel routing cache is disabled, involving an uninitialized pointer and a panic.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:30.552-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:42.923-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:07.347-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:98970"/>
          <criterion comment="kernel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:98541"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:98474"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:98814"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:99010"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:99124"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:98950"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:98954"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:98812"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:98779"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:98808"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:98976"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21776" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1385: kdelibs and kdelibs3 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>kdelibs</product>
          <product>kdelibs3</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1385-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1385.html"/>
        <reference source="CESA" ref_id="CESA-2011:1385"/>
        <reference source="CVE" ref_id="CVE-2011-3365" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3365.html"/>
        <description>The KDE SSL Wrapper (KSSL) API in KDE SC 4.6.0 through 4.7.1, and possibly earlier versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:47.308-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:42.838-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:07.221-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="kdelibs-apidocs is earlier than 6:3.5.4-26.el5_7.1" test_ref="oval:org.mitre.oval:tst:98337"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.5.4-26.el5_7.1" test_ref="oval:org.mitre.oval:tst:98646"/>
            <criterion comment="kdelibs is earlier than 6:3.5.4-26.el5_7.1" test_ref="oval:org.mitre.oval:tst:97744"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="kdelibs3-apidocs is earlier than 0:3.5.10-24.el6_1.1" test_ref="oval:org.mitre.oval:tst:98739"/>
            <criterion comment="kdelibs3-devel is earlier than 0:3.5.10-24.el6_1.1" test_ref="oval:org.mitre.oval:tst:98386"/>
            <criterion comment="kdelibs3 is earlier than 0:3.5.10-24.el6_1.1" test_ref="oval:org.mitre.oval:tst:98274"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21774" version="81" class="patch">
      <metadata>
        <title>RHSA-2010:0429: postgresql security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0429-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0429.html"/>
        <reference source="CESA" ref_id="CESA-2010:0429"/>
        <reference source="CVE" ref_id="CVE-2009-4136" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4136.html"/>
        <reference source="CVE" ref_id="CVE-2010-0442" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0442.html"/>
        <reference source="CVE" ref_id="CVE-2010-0733" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0733.html"/>
        <reference source="CVE" ref_id="CVE-2010-1169" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1169.html"/>
        <reference source="CVE" ref_id="CVE-2010-1170" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1170.html"/>
        <reference source="CVE" ref_id="CVE-2010-1975" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1975.html"/>
        <description>PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, and 8.4 before 8.4.4 does not properly check privileges during certain RESET ALL operations, which allows remote authenticated users to remove arbitrary parameter settings via a (1) ALTER USER or (2) ALTER DATABASE statement.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:41.817-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:42.668-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:06.954-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="postgresql-docs is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99407"/>
          <criterion comment="postgresql-devel is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99076"/>
          <criterion comment="postgresql-test is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99057"/>
          <criterion comment="postgresql-contrib is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99327"/>
          <criterion comment="postgresql-libs is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:98986"/>
          <criterion comment="postgresql-tcl is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99355"/>
          <criterion comment="postgresql is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99255"/>
          <criterion comment="postgresql-server is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99366"/>
          <criterion comment="postgresql-pl is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99261"/>
          <criterion comment="postgresql-python is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:99090"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21773" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1371: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1371-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1371.html"/>
        <reference source="CESA" ref_id="CESA-2011:1371"/>
        <reference source="CVE" ref_id="CVE-2011-1091" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1091.html"/>
        <reference source="CVE" ref_id="CVE-2011-3594" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3594.html"/>
        <description>The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a denial of service (crash) via invalid UTF-8 sequences that trigger use of invalid pointers and an out-of-bounds read, related to interactions with certain versions of glib2.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:08.369-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:42.544-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:06.827-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libpurple-perl is earlier than 0:2.6.6-5.el5_7.1" test_ref="oval:org.mitre.oval:tst:98381"/>
          <criterion comment="libpurple is earlier than 0:2.6.6-5.el5_7.1" test_ref="oval:org.mitre.oval:tst:98309"/>
          <criterion comment="finch is earlier than 0:2.6.6-5.el5_7.1" test_ref="oval:org.mitre.oval:tst:98498"/>
          <criterion comment="pidgin is earlier than 0:2.6.6-5.el5_7.1" test_ref="oval:org.mitre.oval:tst:98571"/>
          <criterion comment="finch-devel is earlier than 0:2.6.6-5.el5_7.1" test_ref="oval:org.mitre.oval:tst:98634"/>
          <criterion comment="libpurple-devel is earlier than 0:2.6.6-5.el5_7.1" test_ref="oval:org.mitre.oval:tst:98558"/>
          <criterion comment="pidgin-devel is earlier than 0:2.6.6-5.el5_7.1" test_ref="oval:org.mitre.oval:tst:98529"/>
          <criterion comment="pidgin-perl is earlier than 0:2.6.6-5.el5_7.1" test_ref="oval:org.mitre.oval:tst:98307"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.6.6-5.el5_7.1" test_ref="oval:org.mitre.oval:tst:98567"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21771" version="94" class="patch">
      <metadata>
        <title>RHSA-2011:0370: wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0370-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0370.html"/>
        <reference source="CESA" ref_id="CESA-2011:0370"/>
        <reference source="CVE" ref_id="CVE-2010-3445" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3445.html"/>
        <reference source="CVE" ref_id="CVE-2011-0024" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0024.html"/>
        <reference source="CVE" ref_id="CVE-2011-0538" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0538.html"/>
        <reference source="CVE" ref_id="CVE-2011-1139" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1139.html"/>
        <reference source="CVE" ref_id="CVE-2011-1140" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1140.html"/>
        <reference source="CVE" ref_id="CVE-2011-1141" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1141.html"/>
        <reference source="CVE" ref_id="CVE-2011-1143" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1143.html"/>
        <description>epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark before 1.4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted .pcap file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:55.694-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:42.147-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:06.072-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="wireshark is earlier than 0:1.0.15-1.el5_6.4" test_ref="oval:org.mitre.oval:tst:97641"/>
          <criterion comment="wireshark-gnome is earlier than 0:1.0.15-1.el5_6.4" test_ref="oval:org.mitre.oval:tst:97608"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21765" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:1437: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1437-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1437.html"/>
        <reference source="CESA" ref_id="CESA-2011:1437"/>
        <reference source="CVE" ref_id="CVE-2011-3647" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3647.html"/>
        <reference source="CVE" ref_id="CVE-2011-3648" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3648.html"/>
        <reference source="CVE" ref_id="CVE-2011-3650" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3650.html"/>
        <description>Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 do not properly handle JavaScript files that contain many functions, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted file that is accessed by debugging APIs, as demonstrated by Firebug.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:37.563-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:41.955-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:05.868-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.24-2.el5_7" test_ref="oval:org.mitre.oval:tst:98569"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.24-2.el5_7" test_ref="oval:org.mitre.oval:tst:98706"/>
            <criterion comment="firefox is earlier than 0:3.6.24-3.el5_7" test_ref="oval:org.mitre.oval:tst:98012"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.24-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:98696"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.24-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:97782"/>
            <criterion comment="firefox is earlier than 0:3.6.24-3.el6_1" test_ref="oval:org.mitre.oval:tst:98533"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21761" version="120" class="patch">
      <metadata>
        <title>RHSA-2011:1423: php53 and php security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1423-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1423.html"/>
        <reference source="CESA" ref_id="CESA-2011:1423"/>
        <reference source="CVE" ref_id="CVE-2011-0708" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0708.html"/>
        <reference source="CVE" ref_id="CVE-2011-1148" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1148.html"/>
        <reference source="CVE" ref_id="CVE-2011-1466" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1466.html"/>
        <reference source="CVE" ref_id="CVE-2011-1468" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1468.html"/>
        <reference source="CVE" ref_id="CVE-2011-1469" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1469.html"/>
        <reference source="CVE" ref_id="CVE-2011-1471" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1471.html"/>
        <reference source="CVE" ref_id="CVE-2011-1938" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1938.html"/>
        <reference source="CVE" ref_id="CVE-2011-2202" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2202.html"/>
        <reference source="CVE" ref_id="CVE-2011-2483" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2483.html"/>
        <description>crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext password by leveraging knowledge of a password hash.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:36.883-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:41.664-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:05.184-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98458"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98710"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98212"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98269"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98534"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:97907"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98687"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98415"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98016"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98635"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98477"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98716"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:97825"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98467"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98444"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98054"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98618"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98550"/>
            <criterion comment="php53 is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98358"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98744"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98429"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98742"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98718"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98199"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98708"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98740"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98736"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98625"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:97750"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98512"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98433"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98684"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:97767"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98384"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98636"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98177"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98150"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98661"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98421"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98554"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98445"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98495"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98124"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:97790"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:97890"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98099"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98562"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21758" version="200" class="patch">
      <metadata>
        <title>RHSA-2011:0471: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0471-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0471.html"/>
        <reference source="CVE" ref_id="CVE-2011-0065" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0065.html"/>
        <reference source="CVE" ref_id="CVE-2011-0066" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0066.html"/>
        <reference source="CVE" ref_id="CVE-2011-0067" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0067.html"/>
        <reference source="CVE" ref_id="CVE-2011-0069" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0069.html"/>
        <reference source="CVE" ref_id="CVE-2011-0070" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0070.html"/>
        <reference source="CVE" ref_id="CVE-2011-0071" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0071.html"/>
        <reference source="CVE" ref_id="CVE-2011-0072" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0072.html"/>
        <reference source="CVE" ref_id="CVE-2011-0073" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0073.html"/>
        <reference source="CVE" ref_id="CVE-2011-0074" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0074.html"/>
        <reference source="CVE" ref_id="CVE-2011-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0075.html"/>
        <reference source="CVE" ref_id="CVE-2011-0077" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0077.html"/>
        <reference source="CVE" ref_id="CVE-2011-0078" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0078.html"/>
        <reference source="CVE" ref_id="CVE-2011-0080" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0080.html"/>
        <reference source="CVE" ref_id="CVE-2011-0081" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0081.html"/>
        <reference source="CVE" ref_id="CVE-2011-1202" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1202.html"/>
        <reference source="CESA-2011:0471" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017460.html" ref_id="CESA-2011:0471-CentOS 5"/>
        <description>The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:18.715-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:41.314-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:04.438-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21758 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:29.826-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:14.293-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.17-3.el5_6" test_ref="oval:org.mitre.oval:tst:136898"/>
            <criterion comment="firefox is earlier than 0:3.6.17-1.el5_6" test_ref="oval:org.mitre.oval:tst:137877"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.17-3.el5_6" test_ref="oval:org.mitre.oval:tst:137813"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:3.6.17-1.el6_0" test_ref="oval:org.mitre.oval:tst:97875"/>
            <criterion comment="firefox-debuginfo is earlier than 0:3.6.17-1.el6_0" test_ref="oval:org.mitre.oval:tst:137359"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.17-4.el6_0" test_ref="oval:org.mitre.oval:tst:97757"/>
            <criterion comment="xulrunner-debuginfo is earlier than 0:1.9.2.17-4.el6_0" test_ref="oval:org.mitre.oval:tst:137795"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.17-4.el6_0" test_ref="oval:org.mitre.oval:tst:97834"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:3.6.17-1.el5.centos" test_ref="oval:org.mitre.oval:tst:137848"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.17-3.el5" test_ref="oval:org.mitre.oval:tst:137541"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.17-3.el5" test_ref="oval:org.mitre.oval:tst:137529"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21755" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0029: krb5 security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0029-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0029.html"/>
        <reference source="CESA" ref_id="CESA-2010:0029"/>
        <reference source="CVE" ref_id="CVE-2009-4212" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4212.html"/>
        <description>Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by providing ciphertext with a length that is too short to be valid.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:27.409-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:41.182-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:01.896-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="krb5-libs is earlier than 0:1.6.1-36.el5_4.1" test_ref="oval:org.mitre.oval:tst:99085"/>
          <criterion comment="krb5-devel is earlier than 0:1.6.1-36.el5_4.1" test_ref="oval:org.mitre.oval:tst:98873"/>
          <criterion comment="krb5-server is earlier than 0:1.6.1-36.el5_4.1" test_ref="oval:org.mitre.oval:tst:98797"/>
          <criterion comment="krb5 is earlier than 0:1.6.1-36.el5_4.1" test_ref="oval:org.mitre.oval:tst:98905"/>
          <criterion comment="krb5-workstation is earlier than 0:1.6.1-36.el5_4.1" test_ref="oval:org.mitre.oval:tst:98227"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21749" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:0176: java-1.6.0-openjdk security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0176-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0176.html"/>
        <reference source="CESA" ref_id="CESA-2011:0176"/>
        <reference source="CVE" ref_id="CVE-2010-3860" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3860.html"/>
        <reference source="CVE" ref_id="CVE-2010-4351" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4351.html"/>
        <description>The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7, 1.8 before 1.8.4, and 1.9 before 1.9.4 for Java OpenJDK returns from the checkPermission method instead of throwing an exception in certain circumstances, which might allow context-dependent attackers to bypass the intended security policy by creating instances of ClassLoader.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:53.991-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:40.991-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:01.332-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.17.b17.el5" test_ref="oval:org.mitre.oval:tst:96881"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.17.b17.el5" test_ref="oval:org.mitre.oval:tst:97070"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.17.b17.el5" test_ref="oval:org.mitre.oval:tst:97058"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.17.b17.el5" test_ref="oval:org.mitre.oval:tst:97016"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.17.b17.el5" test_ref="oval:org.mitre.oval:tst:96711"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21743" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0163: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0163-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0163.html"/>
        <reference source="CESA" ref_id="CESA-2011:0163"/>
        <reference source="CVE" ref_id="CVE-2010-4526" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4526.html"/>
        <description>Race condition in the sctp_icmp_proto_unreachable function in net/sctp/input.c in Linux kernel 2.6.11-rc2 through 2.6.33 allows remote attackers to cause a denial of service (panic) via an ICMP unreachable message to a socket that is already locked by a user, which causes the socket to be freed and triggers list corruption, related to the sctp_wait_for_connect function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:38.579-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:40.761-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:00.621-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:96862"/>
          <criterion comment="kernel is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:97137"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:96973"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:97156"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:97057"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:97037"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:96200"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:96672"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:97031"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:96247"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:96521"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:96859"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21742" version="146" class="patch">
      <metadata>
        <title>RHSA-2011:0860: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0860-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0860.html"/>
        <reference source="CVE" ref_id="CVE-2011-0802" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0802.html"/>
        <reference source="CVE" ref_id="CVE-2011-0814" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0814.html"/>
        <reference source="CVE" ref_id="CVE-2011-0862" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0862.html"/>
        <reference source="CVE" ref_id="CVE-2011-0863" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0863.html"/>
        <reference source="CVE" ref_id="CVE-2011-0864" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0864.html"/>
        <reference source="CVE" ref_id="CVE-2011-0865" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0865.html"/>
        <reference source="CVE" ref_id="CVE-2011-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0867.html"/>
        <reference source="CVE" ref_id="CVE-2011-0868" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0868.html"/>
        <reference source="CVE" ref_id="CVE-2011-0869" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0869.html"/>
        <reference source="CVE" ref_id="CVE-2011-0871" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0871.html"/>
        <reference source="CVE" ref_id="CVE-2011-0873" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0873.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, and 5.0 Update 29 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:41.687-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:40.514-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:00.109-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97917"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97961"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98145"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97755"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98049"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97900"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97642"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98013"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97807"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97990"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98038"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97181"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21741" version="42" class="patch">
      <metadata>
        <title>RHSA-2010:0968: thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0968-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0968.html"/>
        <reference source="CVE" ref_id="CVE-2010-3767" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3767.html"/>
        <reference source="CVE" ref_id="CVE-2010-3772" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3772.html"/>
        <reference source="CVE" ref_id="CVE-2010-3776" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3776.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:52.131-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:40.422-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:59.790-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-13.el5_5" test_ref="oval:org.mitre.oval:tst:100106"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21740" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0845: bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind97</product>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0845-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0845.html"/>
        <reference source="CVE" ref_id="CVE-2011-1910" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1910.html"/>
        <reference source="CESA-2011:0845" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-May/017599.html" ref_id="CESA-2011:0845-CentOS 5"/>
        <description>Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:00.920-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:40.338-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:59.567-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21740 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:24.146-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:13.819-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind97 is earlier than 32:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:137605"/>
            <criterion comment="bind97-chroot is earlier than 32:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:137688"/>
            <criterion comment="bind97-devel is earlier than 32:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:137801"/>
            <criterion comment="bind97-libs is earlier than 32:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:137715"/>
            <criterion comment="bind97-utils is earlier than 32:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:136906"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:97847"/>
            <criterion comment="bind-chroot is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:98025"/>
            <criterion comment="bind-debuginfo is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:137885"/>
            <criterion comment="bind-devel is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:97178"/>
            <criterion comment="bind-libs is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:97153"/>
            <criterion comment="bind-sdb is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:98044"/>
            <criterion comment="bind-utils is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:98017"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21735" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0153: exim security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>exim</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0153-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0153.html"/>
        <reference source="CESA" ref_id="CESA-2011:0153"/>
        <reference source="CVE" ref_id="CVE-2010-4345" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4345.html"/>
        <description>Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:10.209-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:40.190-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:59.270-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="exim-mon is earlier than 0:4.63-5.el5_6.2" test_ref="oval:org.mitre.oval:tst:97042"/>
          <criterion comment="exim is earlier than 0:4.63-5.el5_6.2" test_ref="oval:org.mitre.oval:tst:97078"/>
          <criterion comment="exim-sa is earlier than 0:4.63-5.el5_6.2" test_ref="oval:org.mitre.oval:tst:97149"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21732" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1000: rgmanager security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>rgmanager</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1000-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1000.html"/>
        <reference source="CESA" ref_id="CESA-2011:1000"/>
        <reference source="CVE" ref_id="CVE-2010-3389" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3389.html"/>
        <description>The (1) SAPDatabase and (2) SAPInstance scripts in OCF Resource Agents (aka resource-agents or cluster-agents) 1.0.3 in Linux-HA place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:42.688-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:40.121-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:59.153-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="rgmanager is earlier than 0:2.0.52-21.el5" test_ref="oval:org.mitre.oval:tst:97706"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21726" version="302" class="patch">
      <metadata>
        <title>RHSA-2011:0301: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0301-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0301.html"/>
        <reference source="CVE" ref_id="CVE-2011-0562" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0562.html"/>
        <reference source="CVE" ref_id="CVE-2011-0563" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0563.html"/>
        <reference source="CVE" ref_id="CVE-2011-0565" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0565.html"/>
        <reference source="CVE" ref_id="CVE-2011-0566" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0566.html"/>
        <reference source="CVE" ref_id="CVE-2011-0567" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0567.html"/>
        <reference source="CVE" ref_id="CVE-2011-0585" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0585.html"/>
        <reference source="CVE" ref_id="CVE-2011-0586" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0586.html"/>
        <reference source="CVE" ref_id="CVE-2011-0587" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0587.html"/>
        <reference source="CVE" ref_id="CVE-2011-0589" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0589.html"/>
        <reference source="CVE" ref_id="CVE-2011-0590" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0590.html"/>
        <reference source="CVE" ref_id="CVE-2011-0591" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0591.html"/>
        <reference source="CVE" ref_id="CVE-2011-0592" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0592.html"/>
        <reference source="CVE" ref_id="CVE-2011-0593" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0593.html"/>
        <reference source="CVE" ref_id="CVE-2011-0594" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0594.html"/>
        <reference source="CVE" ref_id="CVE-2011-0595" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0595.html"/>
        <reference source="CVE" ref_id="CVE-2011-0596" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0596.html"/>
        <reference source="CVE" ref_id="CVE-2011-0598" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0598.html"/>
        <reference source="CVE" ref_id="CVE-2011-0599" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0599.html"/>
        <reference source="CVE" ref_id="CVE-2011-0600" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0600.html"/>
        <reference source="CVE" ref_id="CVE-2011-0602" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0602.html"/>
        <reference source="CVE" ref_id="CVE-2011-0603" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0603.html"/>
        <reference source="CVE" ref_id="CVE-2011-0604" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0604.html"/>
        <reference source="CVE" ref_id="CVE-2011-0606" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0606.html"/>
        <description>Stack-based buffer overflow in rt3d.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors related to a crafted length value, a different vulnerability than CVE-2011-0563 and CVE-2011-0589.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:12.818-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:39.628-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:58.530-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.4.2-1.el5" test_ref="oval:org.mitre.oval:tst:96576"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.2-1.el5" test_ref="oval:org.mitre.oval:tst:97249"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.4.2-3.el6_0" test_ref="oval:org.mitre.oval:tst:97437"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.2-3.el6_0" test_ref="oval:org.mitre.oval:tst:97545"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21725" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:1797: perl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>perl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1797-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1797.html"/>
        <reference source="CESA" ref_id="CESA-2011:1797"/>
        <reference source="CVE" ref_id="CVE-2010-2761" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2761.html"/>
        <reference source="CVE" ref_id="CVE-2010-4410" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4410.html"/>
        <reference source="CVE" ref_id="CVE-2011-3597" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3597.html"/>
        <description>Eval injection vulnerability in the Digest module before 1.17 for Perl allows context-dependent attackers to execute arbitrary commands via the new constructor.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:27.547-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:39.515-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:58.379-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="perl-suidperl is earlier than 4:5.8.8-32.el5_7.6" test_ref="oval:org.mitre.oval:tst:98497"/>
          <criterion comment="perl is earlier than 4:5.8.8-32.el5_7.6" test_ref="oval:org.mitre.oval:tst:98387"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21724" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1165: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1165-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1165.html"/>
        <reference source="CESA" ref_id="CESA-2011:1165"/>
        <reference source="CVE" ref_id="CVE-2011-2982" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2982.html"/>
        <reference source="CVE" ref_id="CVE-2011-2983" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2983.html"/>
        <description>Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, SeaMonkey 1.x and 2.x, and possibly other products does not properly handle the RegExp.input property, which allows remote attackers to bypass the Same Origin Policy and read data from a different domain via a crafted web site, possibly related to a use-after-free.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:06.864-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:39.432-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:58.280-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-21.el5" test_ref="oval:org.mitre.oval:tst:97402"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21716" version="224" class="patch">
      <metadata>
        <title>RHSA-2010:0768: java-1.6.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0768-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0768.html"/>
        <reference source="CESA" ref_id="CESA-2010:0768"/>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html"/>
        <reference source="CVE" ref_id="CVE-2010-3541" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3541.html"/>
        <reference source="CVE" ref_id="CVE-2010-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3548.html"/>
        <reference source="CVE" ref_id="CVE-2010-3549" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3549.html"/>
        <reference source="CVE" ref_id="CVE-2010-3551" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3551.html"/>
        <reference source="CVE" ref_id="CVE-2010-3553" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3553.html"/>
        <reference source="CVE" ref_id="CVE-2010-3554" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3554.html"/>
        <reference source="CVE" ref_id="CVE-2010-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3557.html"/>
        <reference source="CVE" ref_id="CVE-2010-3561" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3561.html"/>
        <reference source="CVE" ref_id="CVE-2010-3562" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3562.html"/>
        <reference source="CVE" ref_id="CVE-2010-3564" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3564.html"/>
        <reference source="CVE" ref_id="CVE-2010-3565" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3565.html"/>
        <reference source="CVE" ref_id="CVE-2010-3567" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3567.html"/>
        <reference source="CVE" ref_id="CVE-2010-3568" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3568.html"/>
        <reference source="CVE" ref_id="CVE-2010-3569" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3569.html"/>
        <reference source="CVE" ref_id="CVE-2010-3573" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3573.html"/>
        <reference source="CVE" ref_id="CVE-2010-3574" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3574.html"/>
        <description>Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable downstream vendor that HttpURLConnection does not properly check for the allowHttpTrace permission, which allows untrusted code to perform HTTP TRACE requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:12.750-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:38.400-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:56.967-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.16.b17.el5" test_ref="oval:org.mitre.oval:tst:99351"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.16.b17.el5" test_ref="oval:org.mitre.oval:tst:99464"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.16.b17.el5" test_ref="oval:org.mitre.oval:tst:99567"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.16.b17.el5" test_ref="oval:org.mitre.oval:tst:99285"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.16.b17.el5" test_ref="oval:org.mitre.oval:tst:99531"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21713" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0214: java-1.6.0-openjdk security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0214-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0214.html"/>
        <reference source="CVE" ref_id="CVE-2010-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4476.html"/>
        <reference source="CESA-2011:0214" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017311.html" ref_id="CESA-2011:0214-CentOS 5"/>
        <description>The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:26.903-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:38.337-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:56.882-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21713 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:26.820-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:13.428-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.18.b17.el5" test_ref="oval:org.mitre.oval:tst:137875"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.18.b17.el5" test_ref="oval:org.mitre.oval:tst:137610"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.18.b17.el5" test_ref="oval:org.mitre.oval:tst:137775"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.18.b17.el5" test_ref="oval:org.mitre.oval:tst:137575"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.18.b17.el5" test_ref="oval:org.mitre.oval:tst:137751"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:97461"/>
            <criterion comment="java-1.6.0-openjdk-debuginfo is earlier than 1:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:137857"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:97143"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:97316"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:97445"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:97379"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21712" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0428: dhcp security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>dhcp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0428-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0428.html"/>
        <reference source="CVE" ref_id="CVE-2011-0997" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0997.html"/>
        <reference source="CESA-2011:0428" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017295.html" ref_id="CESA-2011:0428-CentOS 5"/>
        <description>dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstrated by a hostname that is provided to dhclient-script.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:12.343-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:38.277-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:56.804-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21712 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:23.375-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:13.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dhcp is earlier than 12:3.0.5-23.el5_6.4" test_ref="oval:org.mitre.oval:tst:137712"/>
            <criterion comment="dhcp-devel is earlier than 12:3.0.5-23.el5_6.4" test_ref="oval:org.mitre.oval:tst:137895"/>
            <criterion comment="libdhcp4client-devel is earlier than 12:3.0.5-23.el5_6.4" test_ref="oval:org.mitre.oval:tst:137676"/>
            <criterion comment="dhclient is earlier than 12:3.0.5-23.el5_6.4" test_ref="oval:org.mitre.oval:tst:137671"/>
            <criterion comment="libdhcp4client is earlier than 12:3.0.5-23.el5_6.4" test_ref="oval:org.mitre.oval:tst:137734"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dhclient is earlier than 12:4.1.1-12.P1.el6_0.4" test_ref="oval:org.mitre.oval:tst:97534"/>
            <criterion comment="dhcp is earlier than 12:4.1.1-12.P1.el6_0.4" test_ref="oval:org.mitre.oval:tst:97866"/>
            <criterion comment="dhcp-debuginfo is earlier than 12:4.1.1-12.P1.el6_0.4" test_ref="oval:org.mitre.oval:tst:137889"/>
            <criterion comment="dhcp-devel is earlier than 12:4.1.1-12.P1.el6_0.4" test_ref="oval:org.mitre.oval:tst:97717"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21710" version="81" class="patch">
      <metadata>
        <title>RHSA-2011:0838: gimp security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gimp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0838-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0838.html"/>
        <reference source="CESA" ref_id="CESA-2011:0838"/>
        <reference source="CVE" ref_id="CVE-2009-1570" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1570.html"/>
        <reference source="CVE" ref_id="CVE-2010-4540" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4540.html"/>
        <reference source="CVE" ref_id="CVE-2010-4541" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4541.html"/>
        <reference source="CVE" ref_id="CVE-2010-4542" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4542.html"/>
        <reference source="CVE" ref_id="CVE-2010-4543" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4543.html"/>
        <reference source="CVE" ref_id="CVE-2011-1178" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1178.html"/>
        <description>Multiple integer overflows in the load_image function in file-pcx.c in the Personal Computer Exchange (PCX) plugin in GIMP 2.6.x and earlier allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PCX image that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:23.485-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:38.131-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:56.635-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="gimp-libs is earlier than 2:2.2.13-2.0.7.el5_6.2" test_ref="oval:org.mitre.oval:tst:98059"/>
          <criterion comment="gimp-devel is earlier than 2:2.2.13-2.0.7.el5_6.2" test_ref="oval:org.mitre.oval:tst:97619"/>
          <criterion comment="gimp is earlier than 2:2.2.13-2.0.7.el5_6.2" test_ref="oval:org.mitre.oval:tst:97870"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21707" version="55" class="patch">
      <metadata>
        <title>RHSA-2014:0133: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0133-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0133.html"/>
        <reference source="CESA" ref_id="CESA-2014:0133"/>
        <reference source="CVE" ref_id="CVE-2014-1477" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1477.html"/>
        <reference source="CVE" ref_id="CVE-2014-1479" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1479.html"/>
        <reference source="CVE" ref_id="CVE-2014-1481" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1481.html"/>
        <reference source="CVE" ref_id="CVE-2014-1482" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1482.html"/>
        <reference source="CVE" ref_id="CVE-2014-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1486.html"/>
        <reference source="CVE" ref_id="CVE-2014-1487" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1487.html"/>
        <description>The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:15.974-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:35.023-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:11.697-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21707 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:15.711-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:09.096-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21707 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:39.703-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:52.145-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:24.3.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:100278"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="thunderbird is earlier than 0:24.3.0-2.el6_5" test_ref="oval:org.mitre.oval:tst:100038"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="libvirt-devel is earlier than 0:0.10.2-29.el6_5.3" test_ref="oval:org.mitre.oval:tst:113897"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.10.2-29.el6_5.3" test_ref="oval:org.mitre.oval:tst:113478"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21699" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:0196: php53 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>php53</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0196-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0196.html"/>
        <reference source="CESA" ref_id="CESA-2011:0196"/>
        <reference source="CVE" ref_id="CVE-2010-3710" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3710.html"/>
        <reference source="CVE" ref_id="CVE-2010-4156" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4156.html"/>
        <reference source="CVE" ref_id="CVE-2010-4645" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4645.html"/>
        <description>strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to cause a denial of service (infinite loop) via a certain floating-point value in scientific notation, which is not properly handled in x87 FPU registers, as demonstrated using 2.2250738585072011e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:31.637-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:37.766-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:56.194-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:96921"/>
          <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:96926"/>
          <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97299"/>
          <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97159"/>
          <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97375"/>
          <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97342"/>
          <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97088"/>
          <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97049"/>
          <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97043"/>
          <criterion comment="php53 is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97367"/>
          <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97290"/>
          <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97306"/>
          <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97330"/>
          <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:96979"/>
          <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97285"/>
          <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97135"/>
          <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97373"/>
          <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:96753"/>
          <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97334"/>
          <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97382"/>
          <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:97289"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21697" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0451: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0451-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0451.html"/>
        <reference source="CVE" ref_id="CVE-2011-0611" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0611.html"/>
        <description>Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:58.461-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:37.591-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:55.913-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.2.159.1-1.el5" test_ref="oval:org.mitre.oval:tst:97697"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.2.159.1-1.el6" test_ref="oval:org.mitre.oval:tst:97749"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21692" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0356: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0356-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0356.html"/>
        <reference source="CVE" ref_id="CVE-2010-0886" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0886.html"/>
        <reference source="CVE" ref_id="CVE-2010-0887" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0887.html"/>
        <description>Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business JDK and JRE 6 Update 18 and 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:42.168-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:37.237-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:55.394-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.20-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99248"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.20-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99272"/>
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.20-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99274"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.20-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99384"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.20-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99052"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.20-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99267"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21691" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0427: spice-xpi security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>spice-xpi</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0427-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0427.html"/>
        <reference source="CESA" ref_id="CESA-2011:0427"/>
        <reference source="CVE" ref_id="CVE-2011-1179" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1179.html"/>
        <description>The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) plugin/nsScriptablePeer.cpp and (2) plugin/plugin.cpp, which trigger multiple uses of an uninitialized pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:07.534-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:37.167-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:55.300-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="spice-xpi is earlier than 0:2.2-2.3.el5_6.1" test_ref="oval:org.mitre.oval:tst:97626"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21690" version="82" class="patch">
      <metadata>
        <title>RHSA-2011:0490: java-1.4.2-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.4.2-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0490-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0490.html"/>
        <reference source="CVE" ref_id="CVE-2010-4447" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4447.html"/>
        <reference source="CVE" ref_id="CVE-2010-4448" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4448.html"/>
        <reference source="CVE" ref_id="CVE-2010-4454" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4454.html"/>
        <reference source="CVE" ref_id="CVE-2010-4462" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4462.html"/>
        <reference source="CVE" ref_id="CVE-2010-4465" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4465.html"/>
        <reference source="CVE" ref_id="CVE-2010-4466" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4466.html"/>
        <reference source="CVE" ref_id="CVE-2010-4473" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4473.html"/>
        <reference source="CVE" ref_id="CVE-2010-4475" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4475.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:24.967-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:36.939-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:55.032-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.9-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97858"/>
          <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.9-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:96930"/>
          <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.9-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97702"/>
          <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.9-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97817"/>
          <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.9-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97737"/>
          <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.9-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97786"/>
          <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.9-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97398"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21689" version="159" class="patch">
      <metadata>
        <title>RHSA-2010:0501: firefox security, bug fix, and enhancement update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>devhelp</product>
          <product>esc</product>
          <product>firefox</product>
          <product>gnome-python2-extras</product>
          <product>totem</product>
          <product>xulrunner</product>
          <product>yelp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0501-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0501.html"/>
        <reference source="CESA" ref_id="CESA-2010:0501"/>
        <reference source="CVE" ref_id="CVE-2008-5913" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5913.html"/>
        <reference source="CVE" ref_id="CVE-2009-5017" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-5017.html"/>
        <reference source="CVE" ref_id="CVE-2010-0182" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0182.html"/>
        <reference source="CVE" ref_id="CVE-2010-1121" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1121.html"/>
        <reference source="CVE" ref_id="CVE-2010-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1125.html"/>
        <reference source="CVE" ref_id="CVE-2010-1196" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1196.html"/>
        <reference source="CVE" ref_id="CVE-2010-1197" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1197.html"/>
        <reference source="CVE" ref_id="CVE-2010-1198" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1198.html"/>
        <reference source="CVE" ref_id="CVE-2010-1199" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1199.html"/>
        <reference source="CVE" ref_id="CVE-2010-1200" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1200.html"/>
        <reference source="CVE" ref_id="CVE-2010-1202" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1202.html"/>
        <reference source="CVE" ref_id="CVE-2010-1203" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1203.html"/>
        <description>The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger an assertion failure in jstracer.cpp.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:13.452-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:36.599-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:54.619-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="devhelp is earlier than 0:0.12-21.el5" test_ref="oval:org.mitre.oval:tst:99121"/>
          <criterion comment="devhelp-devel is earlier than 0:0.12-21.el5" test_ref="oval:org.mitre.oval:tst:99466"/>
          <criterion comment="gnome-python2-gtkhtml2 is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:99580"/>
          <criterion comment="gnome-python2-libegg is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:99546"/>
          <criterion comment="gnome-python2-gtkmozembed is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:99486"/>
          <criterion comment="gnome-python2-gtkspell is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:99483"/>
          <criterion comment="gnome-python2-extras is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:98996"/>
          <criterion comment="esc is earlier than 0:1.1.0-12.el5" test_ref="oval:org.mitre.oval:tst:99522"/>
          <criterion comment="totem is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:99227"/>
          <criterion comment="totem-mozplugin is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:99413"/>
          <criterion comment="totem-devel is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:99451"/>
          <criterion comment="yelp is earlier than 0:2.16.0-26.el5" test_ref="oval:org.mitre.oval:tst:98642"/>
          <criterion comment="firefox is earlier than 0:3.6.4-8.el5" test_ref="oval:org.mitre.oval:tst:99572"/>
          <criterion comment="xulrunner is earlier than 0:1.9.2.4-10.el5" test_ref="oval:org.mitre.oval:tst:98672"/>
          <criterion comment="xulrunner-devel is earlier than 0:1.9.2.4-10.el5" test_ref="oval:org.mitre.oval:tst:99385"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21684" version="7" class="patch">
      <metadata>
        <title>RHSA-2011:0472: nss security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>nss</product>
          <product>nss-util</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0472-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0472.html"/>
        <reference source="CESA-2011:0472" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017458.html" ref_id="CESA-2011:0472-CentOS 5"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the development of security-enabled client and server applications.

This erratum blacklists a small number of HTTPS certificates by adding
them, flagged as untrusted, to the NSS Builtin Object Token (the
libnssckbi.so library) certificate store. (BZ#689430)

Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not blacklist the certificates for applications that use the
NSS library, but do not use the NSS Builtin Object Token (such as curl).

All NSS users should upgrade to these updated packages, which correct this
issue. After installing the update, applications using NSS must be
restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:13.426-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:36.486-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:54.392-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21684 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:37.778-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:41.100-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21684 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:08.517-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:12.770-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-devel is earlier than 0:3.12.8-4.el5_6" test_ref="oval:org.mitre.oval:tst:136908"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.8-4.el5_6" test_ref="oval:org.mitre.oval:tst:137680"/>
            <criterion comment="nss is earlier than 0:3.12.8-4.el5_6" test_ref="oval:org.mitre.oval:tst:137879"/>
            <criterion comment="nss-tools is earlier than 0:3.12.8-4.el5_6" test_ref="oval:org.mitre.oval:tst:137837"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss is earlier than 0:3.12.8-3.el6_0" test_ref="oval:org.mitre.oval:tst:97681"/>
            <criterion comment="nss-debuginfo is earlier than 0:3.12.8-3.el6_0" test_ref="oval:org.mitre.oval:tst:137770"/>
            <criterion comment="nss-devel is earlier than 0:3.12.8-3.el6_0" test_ref="oval:org.mitre.oval:tst:97411"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.8-3.el6_0" test_ref="oval:org.mitre.oval:tst:97578"/>
            <criterion comment="nss-sysinit is earlier than 0:3.12.8-3.el6_0" test_ref="oval:org.mitre.oval:tst:97712"/>
            <criterion comment="nss-tools is earlier than 0:3.12.8-3.el6_0" test_ref="oval:org.mitre.oval:tst:97833"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21680" version="185" class="patch">
      <metadata>
        <title>RHSA-2011:0004: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0004-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0004.html"/>
        <reference source="CESA" ref_id="CESA-2011:0004"/>
        <reference source="CVE" ref_id="CVE-2010-3432" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3432.html"/>
        <reference source="CVE" ref_id="CVE-2010-3442" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3442.html"/>
        <reference source="CVE" ref_id="CVE-2010-3699" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3699.html"/>
        <reference source="CVE" ref_id="CVE-2010-3858" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3858.html"/>
        <reference source="CVE" ref_id="CVE-2010-3859" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3859.html"/>
        <reference source="CVE" ref_id="CVE-2010-3865" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3865.html"/>
        <reference source="CVE" ref_id="CVE-2010-3876" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3876.html"/>
        <reference source="CVE" ref_id="CVE-2010-3880" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3880.html"/>
        <reference source="CVE" ref_id="CVE-2010-4083" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4083.html"/>
        <reference source="CVE" ref_id="CVE-2010-4157" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4157.html"/>
        <reference source="CVE" ref_id="CVE-2010-4161" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4161.html"/>
        <reference source="CVE" ref_id="CVE-2010-4242" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4242.html"/>
        <reference source="CVE" ref_id="CVE-2010-4247" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4247.html"/>
        <reference source="CVE" ref_id="CVE-2010-4248" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4248.html"/>
        <description>Race condition in the __exit_signal function in kernel/exit.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors related to multithreaded exec, the use of a thread group leader in kernel/posix-cpu-timers.c, and the selection of a new thread group leader in the de_thread function in fs/exec.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:48.080-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:36.157-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:53.941-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:96624"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:96942"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:96805"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:96781"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:96727"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:96851"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:96642"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:96213"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:96976"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:97032"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:96827"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:96049"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21679" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0028: kvm security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0028-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0028.html"/>
        <reference source="CVE" ref_id="CVE-2010-4525" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4525.html"/>
        <description>Linux kernel 2.6.33 and 2.6.34.y does not initialize the kvm_vcpu_events->interrupt.pad structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:13.758-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:36.089-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:53.824-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kvm-qemu-img is earlier than 0:83-224.el5" test_ref="oval:org.mitre.oval:tst:96838"/>
          <criterion comment="kvm is earlier than 0:83-224.el5" test_ref="oval:org.mitre.oval:tst:97019"/>
          <criterion comment="kmod-kvm is earlier than 0:83-224.el5" test_ref="oval:org.mitre.oval:tst:96833"/>
          <criterion comment="kmod-kvm-debug is earlier than 0:83-224.el5" test_ref="oval:org.mitre.oval:tst:96337"/>
          <criterion comment="kvm-tools is earlier than 0:83-224.el5" test_ref="oval:org.mitre.oval:tst:96903"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21665" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1512: libxml2 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1512-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1512.html"/>
        <reference source="CESA" ref_id="CESA-2012:1512"/>
        <reference source="CVE" ref_id="CVE-2012-5134" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5134.html"/>
        <description>Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:39.254-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:35.934-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:53.594-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.el5_8.6" test_ref="oval:org.mitre.oval:tst:94612"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.el5_8.6" test_ref="oval:org.mitre.oval:tst:94428"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.el5_8.6" test_ref="oval:org.mitre.oval:tst:94892"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:94867"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:94379"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:94940"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:94495"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21661" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:0307: mailman security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>mailman</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0307-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0307.html"/>
        <reference source="CESA" ref_id="CESA-2011:0307"/>
        <reference source="CVE" ref_id="CVE-2008-0564" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0564.html"/>
        <reference source="CVE" ref_id="CVE-2010-3089" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3089.html"/>
        <reference source="CVE" ref_id="CVE-2011-0707" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0707.html"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:49.860-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:35.835-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:53.415-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="mailman is earlier than 3:2.1.9-6.el5_6.1" test_ref="oval:org.mitre.oval:tst:97574"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21660" version="96" class="patch">
      <metadata>
        <title>RHSA-2012:1431: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1431-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1431.html"/>
        <reference source="CVE" ref_id="CVE-2012-5274" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5274.html"/>
        <reference source="CVE" ref_id="CVE-2012-5275" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5275.html"/>
        <reference source="CVE" ref_id="CVE-2012-5276" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5276.html"/>
        <reference source="CVE" ref_id="CVE-2012-5277" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5277.html"/>
        <reference source="CVE" ref_id="CVE-2012-5278" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5278.html"/>
        <reference source="CVE" ref_id="CVE-2012-5279" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5279.html"/>
        <reference source="CVE" ref_id="CVE-2012-5280" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5280.html"/>
        <description>Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-5274, CVE-2012-5275, CVE-2012-5276, and CVE-2012-5277.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:54.611-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:35.657-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:53.166-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21660 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:05.625-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:12.079-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.251-1.el5" test_ref="oval:org.mitre.oval:tst:137431"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.251-1.el6" test_ref="oval:org.mitre.oval:tst:94647"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21659" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1349: rpm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>rpm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1349-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1349.html"/>
        <reference source="CESA" ref_id="CESA-2011:1349"/>
        <reference source="CVE" ref_id="CVE-2011-3378" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3378.html"/>
        <description>RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package with crafted headers and offsets that are not properly handled when a package is queried or installed, related to (1) the regionSwab function, (2) the headerLoad function, and (3) multiple functions in rpmio/rpmpgp.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:08.097-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:35.559-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:53.010-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="rpm is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:98600"/>
            <criterion comment="rpm-libs is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:98576"/>
            <criterion comment="rpm-python is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:98316"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:98481"/>
            <criterion comment="rpm-build is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:98499"/>
            <criterion comment="popt is earlier than 0:1.10.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:98577"/>
            <criterion comment="rpm-devel is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:98357"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="rpm-cron is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:98449"/>
            <criterion comment="rpm is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:98544"/>
            <criterion comment="rpm-libs is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:98501"/>
            <criterion comment="rpm-python is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:98154"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:98400"/>
            <criterion comment="rpm-build is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:97971"/>
            <criterion comment="rpm-devel is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:98377"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21648" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0124: systemtap security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>systemtap</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0124-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0124.html"/>
        <reference source="CESA" ref_id="CESA-2010:0124"/>
        <reference source="CVE" ref_id="CVE-2009-4273" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4273.html"/>
        <reference source="CVE" ref_id="CVE-2010-0411" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0411.html"/>
        <description>Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allow local users to cause a denial of service (script crash, or system crash or hang) via a process with a large number of arguments, leading to a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:01.513-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:35.371-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:52.756-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="systemtap-runtime is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:98847"/>
          <criterion comment="systemtap-testsuite is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:99032"/>
          <criterion comment="systemtap is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:99265"/>
          <criterion comment="systemtap-sdt-devel is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:99268"/>
          <criterion comment="systemtap-client is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:99189"/>
          <criterion comment="systemtap-initscript is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:99216"/>
          <criterion comment="systemtap-server is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:99101"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21646" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1196: system-config-printer security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>system-config-printer</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1196-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1196.html"/>
        <reference source="CESA" ref_id="CESA-2011:1196"/>
        <reference source="CVE" ref_id="CVE-2011-2899" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2899.html"/>
        <description>pysmb.py in system-config-printer 0.6.x and 0.7.x, as used in foomatic-gui and possibly other products, allows remote SMB servers to execute arbitrary commands via shell metacharacters in the (1) NetBIOS or (2) workgroup name, which are not properly handled when searching for network printers.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:10.644-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:34.705-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:52.130-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="system-config-printer-libs is earlier than 0:0.7.32.10-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98395"/>
          <criterion comment="system-config-printer is earlier than 0:0.7.32.10-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98125"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21642" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0394: conga security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>conga</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0394-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0394.html"/>
        <reference source="CESA" ref_id="CESA-2011:0394"/>
        <reference source="CVE" ref_id="CVE-2011-0720" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0720.html"/>
        <description>Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administrative access, read or create arbitrary content, and change the site skin via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:37.843-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:34.275-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:51.565-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="ricci is earlier than 0:0.12.2-24.el5_6.1" test_ref="oval:org.mitre.oval:tst:97682"/>
          <criterion comment="luci is earlier than 0:0.12.2-24.el5_6.1" test_ref="oval:org.mitre.oval:tst:97762"/>
          <criterion comment="conga is earlier than 0:0.12.2-24.el5_6.1" test_ref="oval:org.mitre.oval:tst:97577"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21638" version="68" class="patch">
      <metadata>
        <title>RHSA-2011:0909: ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0909-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0909.html"/>
        <reference source="CESA" ref_id="CESA-2011:0909"/>
        <reference source="CVE" ref_id="CVE-2009-4492" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4492.html"/>
        <reference source="CVE" ref_id="CVE-2010-0541" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0541.html"/>
        <reference source="CVE" ref_id="CVE-2011-0188" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0188.html"/>
        <reference source="CVE" ref_id="CVE-2011-1004" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1004.html"/>
        <reference source="CVE" ref_id="CVE-2011-1005" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1005.html"/>
        <description>The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:56.345-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:25.196-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:50.796-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="ruby-docs is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:98034"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:98003"/>
          <criterion comment="ruby-mode is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:97453"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:98005"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:98040"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:98170"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:98201"/>
          <criterion comment="ruby is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:98157"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:97873"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21631" version="146" class="patch">
      <metadata>
        <title>RHSA-2011:1445: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1445-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1445.html"/>
        <reference source="CVE" ref_id="CVE-2011-2445" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2445.html"/>
        <reference source="CVE" ref_id="CVE-2011-2450" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2450.html"/>
        <reference source="CVE" ref_id="CVE-2011-2451" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2451.html"/>
        <reference source="CVE" ref_id="CVE-2011-2452" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2452.html"/>
        <reference source="CVE" ref_id="CVE-2011-2453" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2453.html"/>
        <reference source="CVE" ref_id="CVE-2011-2454" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2454.html"/>
        <reference source="CVE" ref_id="CVE-2011-2455" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2455.html"/>
        <reference source="CVE" ref_id="CVE-2011-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2456.html"/>
        <reference source="CVE" ref_id="CVE-2011-2457" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2457.html"/>
        <reference source="CVE" ref_id="CVE-2011-2459" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2459.html"/>
        <reference source="CVE" ref_id="CVE-2011-2460" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2460.html"/>
        <description>Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2445, CVE-2011-2451, CVE-2011-2452, CVE-2011-2453, CVE-2011-2454, CVE-2011-2455, and CVE-2011-2459.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:39.608-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:24.778-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:50.281-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.11-1.el5" test_ref="oval:org.mitre.oval:tst:98483"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.11-1.el6" test_ref="oval:org.mitre.oval:tst:98326"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21630" version="198" class="patch">
      <metadata>
        <title>RHSA-2012:1483: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1483-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1483.html"/>
        <reference source="CESA" ref_id="CESA-2012:1483"/>
        <reference source="CVE" ref_id="CVE-2012-4201" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4201.html"/>
        <reference source="CVE" ref_id="CVE-2012-4202" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4202.html"/>
        <reference source="CVE" ref_id="CVE-2012-4207" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4207.html"/>
        <reference source="CVE" ref_id="CVE-2012-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4209.html"/>
        <reference source="CVE" ref_id="CVE-2012-4214" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4214.html"/>
        <reference source="CVE" ref_id="CVE-2012-4215" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4215.html"/>
        <reference source="CVE" ref_id="CVE-2012-4216" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4216.html"/>
        <reference source="CVE" ref_id="CVE-2012-5829" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5829.html"/>
        <reference source="CVE" ref_id="CVE-2012-5830" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5830.html"/>
        <reference source="CVE" ref_id="CVE-2012-5833" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5833.html"/>
        <reference source="CVE" ref_id="CVE-2012-5835" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5835.html"/>
        <reference source="CVE" ref_id="CVE-2012-5839" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5839.html"/>
        <reference source="CVE" ref_id="CVE-2012-5840" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5840.html"/>
        <reference source="CVE" ref_id="CVE-2012-5841" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5841.html"/>
        <reference source="CVE" ref_id="CVE-2012-5842" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5842.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:29.671-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:23.984-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:49.851-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:94901"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.11-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94413"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:94939"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.11-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94864"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21629" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1326: pango security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>pango</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1326-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1326.html"/>
        <reference source="CESA" ref_id="CESA-2011:1326"/>
        <reference source="CVE" ref_id="CVE-2011-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3193.html"/>
        <description>Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:51.030-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:23.916-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:49.722-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="pango-devel is earlier than 0:1.14.9-8.el5_7.3" test_ref="oval:org.mitre.oval:tst:98278"/>
          <criterion comment="pango is earlier than 0:1.14.9-8.el5_7.3" test_ref="oval:org.mitre.oval:tst:98462"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21627" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0318: libtiff security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0318-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0318.html"/>
        <reference source="CVE" ref_id="CVE-2011-0192" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0192.html"/>
        <reference source="CESA-2011:0318" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017361.html" ref_id="CESA-2011:0318-CentOS 5"/>
        <description>Buffer overflow in Fax4Decode in LibTIFF 3.9.4 and possibly other versions, as used in ImageIO in Apple iTunes before 10.2 on Windows and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF Internet Fax image file that has been compressed using CCITT Group 4 encoding, related to the EXPAND2D macro in libtiff/tif_fax3.h.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:18.344-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:23.854-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:49.626-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21627 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:15.792-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:11.778-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-7.el5_6.6" test_ref="oval:org.mitre.oval:tst:137374"/>
            <criterion comment="libtiff is earlier than 0:3.8.2-7.el5_6.6" test_ref="oval:org.mitre.oval:tst:137251"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtiff is earlier than 0:3.9.4-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:96582"/>
            <criterion comment="libtiff-debuginfo is earlier than 0:3.9.4-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:137522"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97364"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97569"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21622" version="172" class="patch">
      <metadata>
        <title>RHSA-2011:0357: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0357-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0357.html"/>
        <reference source="CVE" ref_id="CVE-2010-4422" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4422.html"/>
        <reference source="CVE" ref_id="CVE-2010-4447" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4447.html"/>
        <reference source="CVE" ref_id="CVE-2010-4448" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4448.html"/>
        <reference source="CVE" ref_id="CVE-2010-4452" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4452.html"/>
        <reference source="CVE" ref_id="CVE-2010-4454" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4454.html"/>
        <reference source="CVE" ref_id="CVE-2010-4462" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4462.html"/>
        <reference source="CVE" ref_id="CVE-2010-4463" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4463.html"/>
        <reference source="CVE" ref_id="CVE-2010-4465" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4465.html"/>
        <reference source="CVE" ref_id="CVE-2010-4466" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4466.html"/>
        <reference source="CVE" ref_id="CVE-2010-4467" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4467.html"/>
        <reference source="CVE" ref_id="CVE-2010-4468" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4468.html"/>
        <reference source="CVE" ref_id="CVE-2010-4471" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4471.html"/>
        <reference source="CVE" ref_id="CVE-2010-4473" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4473.html"/>
        <reference source="CVE" ref_id="CVE-2010-4475" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4475.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:24.401-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:22.968-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:48.394-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97115"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97412"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97496"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97570"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97522"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97271"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97465"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97331"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:96645"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97586"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97566"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97177"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:96949"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97474"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97227"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21617" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0616: dbus-glib security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>NetworkManager</product>
          <product>dbus-glib</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0616-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0616.html"/>
        <reference source="CESA" ref_id="CESA-2010:0616"/>
        <reference source="CVE" ref_id="CVE-2010-1172" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1172.html"/>
        <description>DBus-GLib 0.73 disregards the access flag of exported GObject properties, which allows local users to bypass intended access restrictions and possibly cause a denial of service by modifying properties, as demonstrated by properties of the (1) DeviceKit-Power, (2) NetworkManager, and (3) ModemManager services.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:28.400-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:22.792-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:47.882-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="dbus-glib-devel is earlier than 0:0.73-10.el5_5" test_ref="oval:org.mitre.oval:tst:99310"/>
          <criterion comment="dbus-glib is earlier than 0:0.73-10.el5_5" test_ref="oval:org.mitre.oval:tst:99499"/>
          <criterion comment="NetworkManager-glib is earlier than 1:0.7.0-10.el5_5.1" test_ref="oval:org.mitre.oval:tst:98964"/>
          <criterion comment="NetworkManager-gnome is earlier than 1:0.7.0-10.el5_5.1" test_ref="oval:org.mitre.oval:tst:99680"/>
          <criterion comment="NetworkManager-devel is earlier than 1:0.7.0-10.el5_5.1" test_ref="oval:org.mitre.oval:tst:99358"/>
          <criterion comment="NetworkManager-glib-devel is earlier than 1:0.7.0-10.el5_5.1" test_ref="oval:org.mitre.oval:tst:99611"/>
          <criterion comment="NetworkManager is earlier than 1:0.7.0-10.el5_5.1" test_ref="oval:org.mitre.oval:tst:99222"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21616" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0859: cyrus-imapd security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>cyrus-imapd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0859-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0859.html"/>
        <reference source="CVE" ref_id="CVE-2011-1926" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1926.html"/>
        <reference source="CESA-2011:0859" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-June/017612.html" ref_id="CESA-2011:0859-CentOS 5"/>
        <description>The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:20.143-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:22.725-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:47.784-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21616 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:22.093-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:11.290-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cyrus-imapd is earlier than 0:2.3.7-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:137794"/>
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.7-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:137312"/>
            <criterion comment="cyrus-imapd-perl is earlier than 0:2.3.7-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:137725"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.7-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:137863"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cyrus-imapd is earlier than 0:2.3.16-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:98076"/>
            <criterion comment="cyrus-imapd-debuginfo is earlier than 0:2.3.16-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:137763"/>
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:98096"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:98120"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21614" version="200" class="patch">
      <metadata>
        <title>RHSA-2012:1465: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1465-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1465.html"/>
        <reference source="CVE" ref_id="CVE-2012-1531" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1531.html"/>
        <reference source="CVE" ref_id="CVE-2012-3143" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3143.html"/>
        <reference source="CVE" ref_id="CVE-2012-3216" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3216.html"/>
        <reference source="CVE" ref_id="CVE-2012-4820" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4820.html"/>
        <reference source="CVE" ref_id="CVE-2012-4822" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4822.html"/>
        <reference source="CVE" ref_id="CVE-2012-5069" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5069.html"/>
        <reference source="CVE" ref_id="CVE-2012-5071" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5071.html"/>
        <reference source="CVE" ref_id="CVE-2012-5073" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5073.html"/>
        <reference source="CVE" ref_id="CVE-2012-5075" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5075.html"/>
        <reference source="CVE" ref_id="CVE-2012-5079" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5079.html"/>
        <reference source="CVE" ref_id="CVE-2012-5081" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5081.html"/>
        <reference source="CVE" ref_id="CVE-2012-5083" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5083.html"/>
        <reference source="CVE" ref_id="CVE-2012-5084" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5084.html"/>
        <reference source="CVE" ref_id="CVE-2012-5089" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5089.html"/>
        <reference source="CVE" ref_id="CVE-2013-1475" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1475.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "IIOP type reuse management" in ObjectStreamClass.java.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:40.970-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:22.428-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:47.549-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21614 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:08.227-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:09.812-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137182"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137815"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:136914"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137245"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137914"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:136920"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137765"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137560"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94301"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94843"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94718"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94732"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94795"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94316"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94711"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21604" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1256: ghostscript security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>ghostscript</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1256-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1256.html"/>
        <reference source="CESA" ref_id="CESA-2012:1256"/>
        <reference source="CVE" ref_id="CVE-2012-4405" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4405.html"/>
        <description>Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow.  NOTE: this issue is also described as an array index error.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:19.288-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:21.960-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:47.067-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:94323"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:94481"/>
            <criterion comment="ghostscript is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:94158"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:94529"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:93565"/>
            <criterion comment="ghostscript-doc is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:94516"/>
            <criterion comment="ghostscript is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:93913"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21601" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1043: libwpd security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>libwpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1043-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1043.html"/>
        <reference source="CESA" ref_id="CESA-2012:1043"/>
        <reference source="CVE" ref_id="CVE-2012-2149" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2149.html"/>
        <description>The WPXContentListener::_closeTableRow function in WPXContentListener.cpp in libwpd 0.8.8, as used by OpenOffice.org (OOo) before 3.4, allows remote attackers to execute arbitrary code via a crafted Wordperfect .WPD document that causes a negative array index to be used.  NOTE: some sources report this issue as an integer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:31.936-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:21.552-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:46.555-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libwpd-devel is earlier than 0:0.8.7-3.1.el5_8" test_ref="oval:org.mitre.oval:tst:93722"/>
          <criterion comment="libwpd is earlier than 0:0.8.7-3.1.el5_8" test_ref="oval:org.mitre.oval:tst:94001"/>
          <criterion comment="libwpd-tools is earlier than 0:0.8.7-3.1.el5_8" test_ref="oval:org.mitre.oval:tst:93973"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21597" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1445: kernel security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1445-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1445.html"/>
        <reference source="CESA" ref_id="CESA-2012:1445"/>
        <reference source="CVE" ref_id="CVE-2012-2100" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2100.html"/>
        <description>The ext4_fill_flex_info function in fs/ext4/super.c in the Linux kernel before 3.2.2, on the x86 platform and unspecified other platforms, allows user-assisted remote attackers to trigger inconsistent filesystem-groups data and possibly cause a denial of service via a malformed ext4 filesystem containing a super block with a large FLEX_BG group size (aka s_log_groups_per_flex value).  NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4307.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:49.776-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:21.353-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:46.192-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:94800"/>
          <criterion comment="kernel is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:94669"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:94136"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:94577"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:94024"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:94657"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:94805"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:94844"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:94710"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:94796"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:94401"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:94886"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21594" version="187" class="patch">
      <metadata>
        <title>RHSA-2012:1346: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1346-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1346.html"/>
        <reference source="CVE" ref_id="CVE-2012-5248" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5248.html"/>
        <reference source="CVE" ref_id="CVE-2012-5249" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5249.html"/>
        <reference source="CVE" ref_id="CVE-2012-5250" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5250.html"/>
        <reference source="CVE" ref_id="CVE-2012-5251" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5251.html"/>
        <reference source="CVE" ref_id="CVE-2012-5252" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5252.html"/>
        <reference source="CVE" ref_id="CVE-2012-5253" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5253.html"/>
        <reference source="CVE" ref_id="CVE-2012-5254" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5254.html"/>
        <reference source="CVE" ref_id="CVE-2012-5255" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5255.html"/>
        <reference source="CVE" ref_id="CVE-2012-5256" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5256.html"/>
        <reference source="CVE" ref_id="CVE-2012-5257" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5257.html"/>
        <reference source="CVE" ref_id="CVE-2012-5258" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5258.html"/>
        <reference source="CVE" ref_id="CVE-2012-5259" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5259.html"/>
        <reference source="CVE" ref_id="CVE-2012-5260" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5260.html"/>
        <reference source="CVE" ref_id="CVE-2012-5261" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5261.html"/>
        <reference source="CVE" ref_id="CVE-2012-5262" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5262.html"/>
        <reference source="CVE" ref_id="CVE-2012-5263" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5263.html"/>
        <reference source="CVE" ref_id="CVE-2012-5264" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5264.html"/>
        <reference source="CVE" ref_id="CVE-2012-5265" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5265.html"/>
        <reference source="CVE" ref_id="CVE-2012-5266" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5266.html"/>
        <reference source="CVE" ref_id="CVE-2012-5267" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5267.html"/>
        <reference source="CVE" ref_id="CVE-2012-5268" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5268.html"/>
        <reference source="CVE" ref_id="CVE-2012-5269" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5269.html"/>
        <reference source="CVE" ref_id="CVE-2012-5270" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5270.html"/>
        <reference source="CVE" ref_id="CVE-2012-5271" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5271.html"/>
        <reference source="CVE" ref_id="CVE-2012-5272" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5272.html"/>
        <reference source="CVE" ref_id="CVE-2012-5285" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5285.html"/>
        <reference source="CVE" ref_id="CVE-2012-5286" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5286.html"/>
        <reference source="CVE" ref_id="CVE-2012-5287" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5287.html"/>
        <reference source="CVE" ref_id="CVE-2012-5673" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5673.html"/>
        <description>Unspecified vulnerability in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 has unknown impact and attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:09.048-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:20.644-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:45.359-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21594 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:34.047-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:07.196-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.243-1.el5" test_ref="oval:org.mitre.oval:tst:137898"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.243-1.el6" test_ref="oval:org.mitre.oval:tst:93757"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21591" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:0422: postfix security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>postfix</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0422-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0422.html"/>
        <reference source="CESA" ref_id="CESA-2011:0422"/>
        <reference source="CVE" ref_id="CVE-2008-2937" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2937.html"/>
        <reference source="CVE" ref_id="CVE-2011-0411" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0411.html"/>
        <description>The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:27.261-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:20.484-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:45.125-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="postfix-pflogsumm is earlier than 2:2.3.3-2.2.el5_6" test_ref="oval:org.mitre.oval:tst:97653"/>
          <criterion comment="postfix is earlier than 2:2.3.3-2.2.el5_6" test_ref="oval:org.mitre.oval:tst:97808"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21587" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0165: nss security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>nspr</product>
          <product>nss</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0165-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0165.html"/>
        <reference source="CESA" ref_id="CESA-2010:0165"/>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html"/>
        <description>The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:14.209-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:20.408-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:45.021-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="nspr-devel is earlier than 0:4.8.4-1.el5_4" test_ref="oval:org.mitre.oval:tst:99263"/>
          <criterion comment="nspr is earlier than 0:4.8.4-1.el5_4" test_ref="oval:org.mitre.oval:tst:98865"/>
          <criterion comment="nss is earlier than 0:3.12.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:99300"/>
          <criterion comment="nss-tools is earlier than 0:3.12.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:98811"/>
          <criterion comment="nss-devel is earlier than 0:3.12.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:99256"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:99293"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21578" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:1288: libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1288-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1288.html"/>
        <reference source="CESA" ref_id="CESA-2012:1288"/>
        <reference source="CVE" ref_id="CVE-2011-3102" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3102.html"/>
        <reference source="CVE" ref_id="CVE-2012-2807" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2807.html"/>
        <description>Multiple integer overflows in libxml2, as used in Google Chrome before 20.0.1132.43 and other products, on 64-bit Linux platforms allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:04.927-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:19.414-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:43.712-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.el5_8.5" test_ref="oval:org.mitre.oval:tst:94291"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.el5_8.5" test_ref="oval:org.mitre.oval:tst:94654"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.el5_8.5" test_ref="oval:org.mitre.oval:tst:94642"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:94610"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:94685"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:94543"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:94284"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21572" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:1037: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1037-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1037.html"/>
        <reference source="CESA" ref_id="CESA-2012:1037"/>
        <reference source="CVE" ref_id="CVE-2012-2143" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2143.html"/>
        <reference source="CVE" ref_id="CVE-2012-2655" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2655.html"/>
        <description>PostgreSQL 8.3.x before 8.3.19, 8.4.x before 8.4.12, 9.0.x before 9.0.8, and 9.1.x before 9.1.4 allows remote authenticated users to cause a denial of service (server crash) by adding the (1) SECURITY DEFINER or (2) SET attributes to a procedural language's call handler.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:13.811-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:58.960-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:43.081-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql84-server is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93881"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93900"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93926"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93699"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93932"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93797"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93970"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93714"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93347"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93632"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:94042"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93102"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:93554"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:93318"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:94020"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:94103"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:94054"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:93750"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:94075"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:93806"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:93585"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:93947"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21568" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1174: kernel security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1174-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1174.html"/>
        <reference source="CESA" ref_id="CESA-2012:1174"/>
        <reference source="CVE" ref_id="CVE-2012-2313" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2313.html"/>
        <description>The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:34.484-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:58.798-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:42.828-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:94412"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:94404"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:94009"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:94400"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:94173"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:94419"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:94330"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:94409"/>
          <criterion comment="kernel is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:94199"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:94433"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:93980"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:94044"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21567" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:1820: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1820-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1820.html"/>
        <reference source="CESA" ref_id="CESA-2011:1820"/>
        <reference source="CVE" ref_id="CVE-2011-4601" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4601.html"/>
        <reference source="CVE" ref_id="CVE-2011-4602" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4602.html"/>
        <reference source="CVE" ref_id="CVE-2011-4603" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4603.html"/>
        <description>The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted message, a different vulnerability than CVE-2011-3594.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:51.769-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:58.681-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:42.632-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="finch-devel is earlier than 0:2.6.6-5.el5_7.4" test_ref="oval:org.mitre.oval:tst:98581"/>
          <criterion comment="libpurple is earlier than 0:2.6.6-5.el5_7.4" test_ref="oval:org.mitre.oval:tst:98707"/>
          <criterion comment="libpurple-perl is earlier than 0:2.6.6-5.el5_7.4" test_ref="oval:org.mitre.oval:tst:98658"/>
          <criterion comment="pidgin is earlier than 0:2.6.6-5.el5_7.4" test_ref="oval:org.mitre.oval:tst:98237"/>
          <criterion comment="pidgin-perl is earlier than 0:2.6.6-5.el5_7.4" test_ref="oval:org.mitre.oval:tst:98794"/>
          <criterion comment="finch is earlier than 0:2.6.6-5.el5_7.4" test_ref="oval:org.mitre.oval:tst:98810"/>
          <criterion comment="libpurple-devel is earlier than 0:2.6.6-5.el5_7.4" test_ref="oval:org.mitre.oval:tst:98723"/>
          <criterion comment="pidgin-devel is earlier than 0:2.6.6-5.el5_7.4" test_ref="oval:org.mitre.oval:tst:98835"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.6.6-5.el5_7.4" test_ref="oval:org.mitre.oval:tst:98848"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21561" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1090: nss and nspr security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>nspr</product>
          <product>nss</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1090-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1090.html"/>
        <reference source="CESA" ref_id="CESA-2012:1090"/>
        <reference source="CVE" ref_id="CVE-2012-0441" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0441.html"/>
        <description>The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10, allows remote attackers to cause a denial of service (application crash) via a zero-length item, as demonstrated by (1) a zero-length basic constraint or (2) a zero-length field in an OCSP response.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:37.002-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:58.533-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:42.403-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="nspr-devel is earlier than 0:4.9.1-4.el5_8" test_ref="oval:org.mitre.oval:tst:94130"/>
          <criterion comment="nspr is earlier than 0:4.9.1-4.el5_8" test_ref="oval:org.mitre.oval:tst:94051"/>
          <criterion comment="nss-tools is earlier than 0:3.13.5-4.el5_8" test_ref="oval:org.mitre.oval:tst:93766"/>
          <criterion comment="nss is earlier than 0:3.13.5-4.el5_8" test_ref="oval:org.mitre.oval:tst:93927"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.13.5-4.el5_8" test_ref="oval:org.mitre.oval:tst:94166"/>
          <criterion comment="nss-devel is earlier than 0:3.13.5-4.el5_8" test_ref="oval:org.mitre.oval:tst:94112"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21558" version="159" class="patch">
      <metadata>
        <title>RHSA-2011:1380: java-1.6.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1380-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1380.html"/>
        <reference source="CESA" ref_id="CESA-2011:1380"/>
        <reference source="CVE" ref_id="CVE-2011-3389" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3389.html"/>
        <reference source="CVE" ref_id="CVE-2011-3521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3521.html"/>
        <reference source="CVE" ref_id="CVE-2011-3544" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3544.html"/>
        <reference source="CVE" ref_id="CVE-2011-3547" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3547.html"/>
        <reference source="CVE" ref_id="CVE-2011-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3548.html"/>
        <reference source="CVE" ref_id="CVE-2011-3551" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3551.html"/>
        <reference source="CVE" ref_id="CVE-2011-3552" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3552.html"/>
        <reference source="CVE" ref_id="CVE-2011-3553" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3553.html"/>
        <reference source="CVE" ref_id="CVE-2011-3554" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3554.html"/>
        <reference source="CVE" ref_id="CVE-2011-3556" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3556.html"/>
        <reference source="CVE" ref_id="CVE-2011-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3557.html"/>
        <reference source="CVE" ref_id="CVE-2011-3558" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3558.html"/>
        <reference source="CVE" ref_id="CVE-2011-3560" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3560.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and integrity, related to JSSE.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:47.013-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:58.141-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:41.895-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:98587"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:98352"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:98615"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:98606"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:98551"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:98164"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:98189"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:98527"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:98182"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:97671"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21551" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1130: xen security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1130-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1130.html"/>
        <reference source="CESA" ref_id="CESA-2012:1130"/>
        <reference source="CVE" ref_id="CVE-2012-2625" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2625.html"/>
        <description>The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualized guest users to cause a denial of service (memory consumption) via a large (1) bzip2 or (2) lzma compressed kernel image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:47.568-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:57.865-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:41.492-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="xen is earlier than 0:3.0.3-135.el5_8.4" test_ref="oval:org.mitre.oval:tst:93895"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-135.el5_8.4" test_ref="oval:org.mitre.oval:tst:93436"/>
          <criterion comment="xen-libs is earlier than 0:3.0.3-135.el5_8.4" test_ref="oval:org.mitre.oval:tst:93640"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21548" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0423: krb5 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0423-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0423.html"/>
        <reference source="CESA" ref_id="CESA-2010:0423"/>
        <reference source="CVE" ref_id="CVE-2010-1321" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1321.html"/>
        <description>The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticator's checksum field is missing.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:14.623-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:57.715-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:41.281-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="krb5-libs is earlier than 0:1.6.1-36.el5_5.4" test_ref="oval:org.mitre.oval:tst:99391"/>
          <criterion comment="krb5-devel is earlier than 0:1.6.1-36.el5_5.4" test_ref="oval:org.mitre.oval:tst:99111"/>
          <criterion comment="krb5-server is earlier than 0:1.6.1-36.el5_5.4" test_ref="oval:org.mitre.oval:tst:99311"/>
          <criterion comment="krb5 is earlier than 0:1.6.1-36.el5_5.4" test_ref="oval:org.mitre.oval:tst:99220"/>
          <criterion comment="krb5-workstation is earlier than 0:1.6.1-36.el5_5.4" test_ref="oval:org.mitre.oval:tst:98987"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21547" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1264: postgresql security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1264-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1264.html"/>
        <reference source="CESA" ref_id="CESA-2012:1264"/>
        <reference source="CVE" ref_id="CVE-2012-3488" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3488.html"/>
        <description>The libxslt support in contrib/xml2 in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 does not properly restrict access to files and URLs, which allows remote authenticated users to modify data, obtain sensitive information, or trigger outbound traffic to arbitrary external hosts by leveraging (1) stylesheet commands that are permitted by the libxslt security options or (2) an xslt_process feature, related to an XML External Entity (aka XXE) issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:35.753-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:57.596-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:41.158-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="postgresql-server is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:94539"/>
          <criterion comment="postgresql-libs is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:94068"/>
          <criterion comment="postgresql is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:94558"/>
          <criterion comment="postgresql-python is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:94336"/>
          <criterion comment="postgresql-docs is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:94532"/>
          <criterion comment="postgresql-pl is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:94444"/>
          <criterion comment="postgresql-test is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:93772"/>
          <criterion comment="postgresql-devel is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:93609"/>
          <criterion comment="postgresql-contrib is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:94307"/>
          <criterion comment="postgresql-tcl is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:94553"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21545" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1362: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1362-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1362.html"/>
        <reference source="CESA" ref_id="CESA-2012:1362"/>
        <reference source="CVE" ref_id="CVE-2012-4193" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4193.html"/>
        <description>Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and read the properties of a Location object, or execute arbitrary JavaScript code, via a crafted web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:45.046-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:57.491-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:40.864-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-2.el5_8" test_ref="oval:org.mitre.oval:tst:94682"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-2.el5.centos" test_ref="oval:org.mitre.oval:tst:94643"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.8-2.el6_3" test_ref="oval:org.mitre.oval:tst:94674"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.8-2.el6.centos" test_ref="oval:org.mitre.oval:tst:95016"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21544" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1422: openswan security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>openswan</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1422-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1422.html"/>
        <reference source="CESA" ref_id="CESA-2011:1422"/>
        <reference source="CVE" ref_id="CVE-2011-4073" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4073.html"/>
        <description>Use-after-free vulnerability in the cryptographic helper handler functionality in Openswan 2.3.0 through 2.6.36 allows remote authenticated users to cause a denial of service (pluto IKE daemon crash) via vectors related to the (1) quick_outI1_continue and (2) quick_outI1 functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:28.499-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:57.381-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:40.763-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openswan is earlier than 0:2.6.21-5.el5_7.6" test_ref="oval:org.mitre.oval:tst:98644"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.21-5.el5_7.6" test_ref="oval:org.mitre.oval:tst:98117"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openswan is earlier than 0:2.6.32-4.el6_1.4" test_ref="oval:org.mitre.oval:tst:98111"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-4.el6_1.4" test_ref="oval:org.mitre.oval:tst:98724"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21541" version="263" class="patch">
      <metadata>
        <title>RHSA-2012:1350: firefox security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1350-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1350.html"/>
        <reference source="CESA" ref_id="CESA-2012:1350"/>
        <reference source="CVE" ref_id="CVE-2012-1956" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1956.html"/>
        <reference source="CVE" ref_id="CVE-2012-3982" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3982.html"/>
        <reference source="CVE" ref_id="CVE-2012-3986" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3986.html"/>
        <reference source="CVE" ref_id="CVE-2012-3988" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3988.html"/>
        <reference source="CVE" ref_id="CVE-2012-3990" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3990.html"/>
        <reference source="CVE" ref_id="CVE-2012-3991" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3991.html"/>
        <reference source="CVE" ref_id="CVE-2012-3992" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3992.html"/>
        <reference source="CVE" ref_id="CVE-2012-3993" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3993.html"/>
        <reference source="CVE" ref_id="CVE-2012-3994" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3994.html"/>
        <reference source="CVE" ref_id="CVE-2012-3995" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3995.html"/>
        <reference source="CVE" ref_id="CVE-2012-4179" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4179.html"/>
        <reference source="CVE" ref_id="CVE-2012-4180" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4180.html"/>
        <reference source="CVE" ref_id="CVE-2012-4181" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4181.html"/>
        <reference source="CVE" ref_id="CVE-2012-4182" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4182.html"/>
        <reference source="CVE" ref_id="CVE-2012-4183" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4183.html"/>
        <reference source="CVE" ref_id="CVE-2012-4184" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4184.html"/>
        <reference source="CVE" ref_id="CVE-2012-4185" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4185.html"/>
        <reference source="CVE" ref_id="CVE-2012-4186" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4186.html"/>
        <reference source="CVE" ref_id="CVE-2012-4187" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4187.html"/>
        <reference source="CVE" ref_id="CVE-2012-4188" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4188.html"/>
        <description>Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:31.164-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:56.304-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:40.074-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-1.el5_8" test_ref="oval:org.mitre.oval:tst:94485"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-1.el5_8" test_ref="oval:org.mitre.oval:tst:94662"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:10.0.8-1.el5.centos" test_ref="oval:org.mitre.oval:tst:95071"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:10.0.8-1.el5_8" test_ref="oval:org.mitre.oval:tst:94736"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-1.el6_3" test_ref="oval:org.mitre.oval:tst:94408"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-1.el6_3" test_ref="oval:org.mitre.oval:tst:94348"/>
            <criterion comment="firefox is earlier than 0:10.0.8-1.el6_3" test_ref="oval:org.mitre.oval:tst:94541"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94385"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94983"/>
            <criterion comment="firefox is earlier than 0:10.0.8-1.el6.centos" test_ref="oval:org.mitre.oval:tst:95006"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21530" version="81" class="patch">
      <metadata>
        <title>RHSA-2012:1265: libxslt security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libxslt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1265-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1265.html"/>
        <reference source="CESA" ref_id="CESA-2012:1265"/>
        <reference source="CVE" ref_id="CVE-2011-1202" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1202.html"/>
        <reference source="CVE" ref_id="CVE-2011-3970" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3970.html"/>
        <reference source="CVE" ref_id="CVE-2012-2825" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2825.html"/>
        <reference source="CVE" ref_id="CVE-2012-2870" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2870.html"/>
        <reference source="CVE" ref_id="CVE-2012-2871" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2871.html"/>
        <reference source="CVE" ref_id="CVE-2012-2893" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2893.html"/>
        <description>Double free vulnerability in libxslt, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XSL transforms.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:55.547-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:55.148-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:39.331-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxslt-devel is earlier than 0:1.1.17-4.el5_8.3" test_ref="oval:org.mitre.oval:tst:94297"/>
            <criterion comment="libxslt is earlier than 0:1.1.17-4.el5_8.3" test_ref="oval:org.mitre.oval:tst:94515"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.17-4.el5_8.3" test_ref="oval:org.mitre.oval:tst:94580"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxslt-devel is earlier than 0:1.1.26-2.el6_3.1" test_ref="oval:org.mitre.oval:tst:94414"/>
            <criterion comment="libxslt is earlier than 0:1.1.26-2.el6_3.1" test_ref="oval:org.mitre.oval:tst:94308"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.26-2.el6_3.1" test_ref="oval:org.mitre.oval:tst:94603"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21529" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0486: xmlsec1 security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>xmlsec1</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0486-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0486.html"/>
        <reference source="CESA" ref_id="CESA-2011:0486"/>
        <reference source="CVE" ref_id="CVE-2011-1425" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1425.html"/>
        <description>xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:21.182-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:55.032-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:39.208-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="xmlsec1-nss-devel is earlier than 0:1.2.9-8.1.2" test_ref="oval:org.mitre.oval:tst:97540"/>
          <criterion comment="xmlsec1-openssl is earlier than 0:1.2.9-8.1.2" test_ref="oval:org.mitre.oval:tst:97732"/>
          <criterion comment="xmlsec1-nss is earlier than 0:1.2.9-8.1.2" test_ref="oval:org.mitre.oval:tst:97835"/>
          <criterion comment="xmlsec1-gnutls is earlier than 0:1.2.9-8.1.2" test_ref="oval:org.mitre.oval:tst:97831"/>
          <criterion comment="xmlsec1 is earlier than 0:1.2.9-8.1.2" test_ref="oval:org.mitre.oval:tst:97704"/>
          <criterion comment="xmlsec1-gnutls-devel is earlier than 0:1.2.9-8.1.2" test_ref="oval:org.mitre.oval:tst:97176"/>
          <criterion comment="xmlsec1-openssl-devel is earlier than 0:1.2.9-8.1.2" test_ref="oval:org.mitre.oval:tst:97610"/>
          <criterion comment="xmlsec1-devel is earlier than 0:1.2.9-8.1.2" test_ref="oval:org.mitre.oval:tst:97719"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21527" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:1054: libtiff security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1054-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1054.html"/>
        <reference source="CESA" ref_id="CESA-2012:1054"/>
        <reference source="CVE" ref_id="CVE-2012-2088" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2088.html"/>
        <reference source="CVE" ref_id="CVE-2012-2113" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2113.html"/>
        <description>Multiple integer overflows in tiff2pdf in libtiff before 4.0.2 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:05.776-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:54.750-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:38.958-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libtiff is earlier than 0:3.8.2-15.el5_8" test_ref="oval:org.mitre.oval:tst:93166"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-15.el5_8" test_ref="oval:org.mitre.oval:tst:93837"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libtiff is earlier than 0:3.9.4-6.el6_3" test_ref="oval:org.mitre.oval:tst:94058"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-6.el6_3" test_ref="oval:org.mitre.oval:tst:94129"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-6.el6_3" test_ref="oval:org.mitre.oval:tst:94023"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21526" version="172" class="patch">
      <metadata>
        <title>RHSA-2011:0017: Red Hat Enterprise Linux 5.6 kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0017-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0017.html"/>
        <reference source="CVE" ref_id="CVE-2010-3296" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3296.html"/>
        <reference source="CVE" ref_id="CVE-2010-3877" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3877.html"/>
        <reference source="CVE" ref_id="CVE-2010-4072" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4072.html"/>
        <reference source="CVE" ref_id="CVE-2010-4073" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4073.html"/>
        <reference source="CVE" ref_id="CVE-2010-4075" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4075.html"/>
        <reference source="CVE" ref_id="CVE-2010-4080" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4080.html"/>
        <reference source="CVE" ref_id="CVE-2010-4081" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4081.html"/>
        <reference source="CVE" ref_id="CVE-2010-4158" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4158.html"/>
        <reference source="CVE" ref_id="CVE-2010-4238" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4238.html"/>
        <reference source="CVE" ref_id="CVE-2010-4243" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4243.html"/>
        <reference source="CVE" ref_id="CVE-2010-4255" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4255.html"/>
        <reference source="CVE" ref_id="CVE-2010-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4263.html"/>
        <reference source="CVE" ref_id="CVE-2010-4343" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4343.html"/>
        <description>drivers/scsi/bfa/bfa_core.c in the Linux kernel before 2.6.35 does not initialize a certain port data structure, which allows local users to cause a denial of service (system crash) via read operations on an fc_host statistics file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:35.084-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:54.167-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:38.574-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:96696"/>
          <criterion comment="kernel is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:97065"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:96884"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:97038"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:97028"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:97045"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:96476"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:97018"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:96566"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:96078"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:96954"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:96321"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21521" version="55" class="patch">
      <metadata>
        <title>RHSA-2010:0178: Red Hat Enterprise Linux 5.5 kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0178-04" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0178.html"/>
        <reference source="CVE" ref_id="CVE-2009-4027" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4027.html"/>
        <reference source="CVE" ref_id="CVE-2009-4307" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4307.html"/>
        <reference source="CVE" ref_id="CVE-2010-0727" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0727.html"/>
        <reference source="CVE" ref_id="CVE-2010-1188" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1188.html"/>
        <description>Use-after-free vulnerability in net/ipv4/tcp_input.c in the Linux kernel 2.6 before 2.6.20, when IPV6_RECVPKTINFO is set on a listening socket, allows remote attackers to cause a denial of service (kernel panic) via a SYN packet while the socket is in a listening (TCP_LISTEN) state, which is not properly handled and causes the skb structure to be freed.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:26.421-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:53.459-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:37.870-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:98938"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:99118"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:99007"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:98983"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:98891"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:99077"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:99140"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:99207"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:99108"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:99025"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:98961"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:98978"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21520" version="224" class="patch">
      <metadata>
        <title>RHSA-2012:1088: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1088-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1088.html"/>
        <reference source="CESA" ref_id="CESA-2012:1088"/>
        <reference source="CVE" ref_id="CVE-2012-1948" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1948.html"/>
        <reference source="CVE" ref_id="CVE-2012-1950" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1950.html"/>
        <reference source="CVE" ref_id="CVE-2012-1951" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1951.html"/>
        <reference source="CVE" ref_id="CVE-2012-1952" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1952.html"/>
        <reference source="CVE" ref_id="CVE-2012-1953" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1953.html"/>
        <reference source="CVE" ref_id="CVE-2012-1954" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1954.html"/>
        <reference source="CVE" ref_id="CVE-2012-1955" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1955.html"/>
        <reference source="CVE" ref_id="CVE-2012-1957" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1957.html"/>
        <reference source="CVE" ref_id="CVE-2012-1958" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1958.html"/>
        <reference source="CVE" ref_id="CVE-2012-1959" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1959.html"/>
        <reference source="CVE" ref_id="CVE-2012-1961" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1961.html"/>
        <reference source="CVE" ref_id="CVE-2012-1962" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1962.html"/>
        <reference source="CVE" ref_id="CVE-2012-1963" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1963.html"/>
        <reference source="CVE" ref_id="CVE-2012-1964" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1964.html"/>
        <reference source="CVE" ref_id="CVE-2012-1965" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1965.html"/>
        <reference source="CVE" ref_id="CVE-2012-1966" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1966.html"/>
        <reference source="CVE" ref_id="CVE-2012-1967" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1967.html"/>
        <description>Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not properly implement the JavaScript sandbox utility, which allows remote attackers to execute arbitrary JavaScript code with improper privileges via a javascript: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:50.243-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:52.787-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:36.906-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.6-2.el5_8" test_ref="oval:org.mitre.oval:tst:93936"/>
            <criterion comment="xulrunner is earlier than 0:10.0.6-2.el5_8" test_ref="oval:org.mitre.oval:tst:93581"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:10.0.6-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94961"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:10.0.6-1.el5_8" test_ref="oval:org.mitre.oval:tst:93905"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:94048"/>
            <criterion comment="xulrunner is earlier than 0:10.0.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:94164"/>
            <criterion comment="firefox is earlier than 0:10.0.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:94072"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.6-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94749"/>
            <criterion comment="xulrunner is earlier than 0:10.0.6-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94352"/>
            <criterion comment="firefox is earlier than 0:10.0.6-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94776"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21518" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0306: samba3x security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>samba3x</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0306-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0306.html"/>
        <reference source="CESA" ref_id="CESA-2011:0306"/>
        <reference source="CVE" ref_id="CVE-2011-0719" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0719.html"/>
        <description>Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macro, which allows remote attackers to cause a denial of service (stack memory corruption, and infinite loop or daemon crash) by opening a large number of files, related to (1) Winbind or (2) smbd.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:52.317-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:52.681-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:36.743-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="samba3x-swat is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:97556"/>
          <criterion comment="samba3x-doc is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:97183"/>
          <criterion comment="samba3x-client is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:97551"/>
          <criterion comment="samba3x-winbind is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:97478"/>
          <criterion comment="samba3x is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:96737"/>
          <criterion comment="samba3x-winbind-devel is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:97492"/>
          <criterion comment="samba3x-common is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:97417"/>
          <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:97498"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21515" version="5" class="patch">
      <metadata>
        <title>RHSA-2012:1097: glibc security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1097-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1097.html"/>
        <reference source="CESA" ref_id="CESA-2012:1097"/>
        <reference source="CVE" ref_id="CVE-2012-3406" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3406.html"/>
        <description>The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (crash) or possibly execute arbitrary code via a crafted format string using positional parameters and a large number of format specifiers, a different vulnerability than CVE-2012-3404 and CVE-2012-3405.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:37.371-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:52.357-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:36.314-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="glibc-common is earlier than 0:2.5-81.el5_8.4" test_ref="oval:org.mitre.oval:tst:94139"/>
          <criterion comment="glibc is earlier than 0:2.5-81.el5_8.4" test_ref="oval:org.mitre.oval:tst:94088"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-81.el5_8.4" test_ref="oval:org.mitre.oval:tst:93849"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-81.el5_8.4" test_ref="oval:org.mitre.oval:tst:94101"/>
          <criterion comment="nscd is earlier than 0:2.5-81.el5_8.4" test_ref="oval:org.mitre.oval:tst:94119"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-81.el5_8.4" test_ref="oval:org.mitre.oval:tst:93773"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21502" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1267: bind security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1267-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1267.html"/>
        <reference source="CESA" ref_id="CESA-2012:1267"/>
        <reference source="CVE" ref_id="CVE-2012-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4244.html"/>
        <description>ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a long resource record.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:43.931-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:51.337-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:35.256-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="bind-utils is earlier than 30:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:94131"/>
          <criterion comment="caching-nameserver is earlier than 30:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:94455"/>
          <criterion comment="bind-chroot is earlier than 30:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:94535"/>
          <criterion comment="bind-libs is earlier than 30:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:94491"/>
          <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:93706"/>
          <criterion comment="bind is earlier than 30:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:93909"/>
          <criterion comment="bind-devel is earlier than 30:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:94168"/>
          <criterion comment="bind-sdb is earlier than 30:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:94262"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21501" version="44" class="patch">
      <metadata>
        <title>RHSA-2012:1569: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1569-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1569.html"/>
        <reference source="CVE" ref_id="CVE-2012-5676" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5676.html"/>
        <reference source="CVE" ref_id="CVE-2012-5677" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5677.html"/>
        <reference source="CVE" ref_id="CVE-2012-5678" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5678.html"/>
        <description>Adobe Flash Player before 10.3.183.48 and 11.x before 11.5.502.135 on Windows, before 10.3.183.48 and 11.x before 11.5.502.136 on Mac OS X, before 10.3.183.48 and 11.x before 11.2.202.258 on Linux, before 11.1.111.29 on Android 2.x and 3.x, and before 11.1.115.34 on Android 4.x; Adobe AIR before 3.5.0.880 on Windows and before 3.5.0.890 on Mac OS X; and Adobe AIR SDK before 3.5.0.880 on Windows and before 3.5.0.890 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:05.063-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:51.174-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:35.097-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21501 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:06.339-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:06.759-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.258-1.el5" test_ref="oval:org.mitre.oval:tst:137796"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.258-1.el6" test_ref="oval:org.mitre.oval:tst:94561"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21500" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0507: apr security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>apr</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0507-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0507.html"/>
        <reference source="CESA" ref_id="CESA-2011:0507"/>
        <reference source="CVE" ref_id="CVE-2011-0419" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0419.html"/>
        <description>Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:00.001-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:51.002-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:34.990-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="apr-devel is earlier than 0:1.2.7-11.el5_6.4" test_ref="oval:org.mitre.oval:tst:97743"/>
            <criterion comment="apr-docs is earlier than 0:1.2.7-11.el5_6.4" test_ref="oval:org.mitre.oval:tst:97588"/>
            <criterion comment="apr is earlier than 0:1.2.7-11.el5_6.4" test_ref="oval:org.mitre.oval:tst:97624"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="apr-devel is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:97862"/>
            <criterion comment="apr is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:97591"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21498" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:0152: java-1.4.2-ibm security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.4.2-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0152-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0152.html"/>
        <reference source="CVE" ref_id="CVE-2010-1321" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1321.html"/>
        <reference source="CVE" ref_id="CVE-2010-3574" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3574.html"/>
        <description>Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable downstream vendor that HttpURLConnection does not properly check for the allowHttpTrace permission, which allows untrusted code to perform HTTP TRACE requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:33.685-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:45.435-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:34.469-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.8-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:96869"/>
          <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.8-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:96825"/>
          <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.8-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:96559"/>
          <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.8-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:96803"/>
          <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.8-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97062"/>
          <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.8-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:96626"/>
          <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.8-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97023"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21497" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0850: flash-plugin security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0850-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0850.html"/>
        <reference source="CVE" ref_id="CVE-2011-2107" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2107.html"/>
        <description>Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.181.22 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.22 and earlier on Android, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "universal cross-site scripting vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:16.470-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:45.374-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:34.384-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.181.22-1.el5" test_ref="oval:org.mitre.oval:tst:97939"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.3.181.22-1.el6" test_ref="oval:org.mitre.oval:tst:98085"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21496" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1123: bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1123-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1123.html"/>
        <reference source="CESA" ref_id="CESA-2012:1123"/>
        <reference source="CVE" ref_id="CVE-2012-3817" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3817.html"/>
        <description>ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:56.512-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:45.278-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:34.253-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bind is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:93721"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:93566"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:94081"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:93247"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:93963"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:94163"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:94049"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:94122"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bind is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:94192"/>
            <criterion comment="bind-chroot is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:94170"/>
            <criterion comment="bind-sdb is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:94208"/>
            <criterion comment="bind-libs is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:94079"/>
            <criterion comment="bind-devel is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:94099"/>
            <criterion comment="bind-utils is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:94087"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21491" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0841: systemtap security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>systemtap</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0841-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0841.html"/>
        <reference source="CESA" ref_id="CESA-2011:0841"/>
        <reference source="CVE" ref_id="CVE-2011-1769" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1769.html"/>
        <description>SystemTap 1.4 and earlier, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted ELF program with DWARF expressions that are not properly handled by a stap script that performs context variable access.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:19.995-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:45.032-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:33.862-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="systemtap-testsuite is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:97806"/>
          <criterion comment="systemtap-runtime is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:97988"/>
          <criterion comment="systemtap is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:97589"/>
          <criterion comment="systemtap-sdt-devel is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:97903"/>
          <criterion comment="systemtap-client is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:97148"/>
          <criterion comment="systemtap-initscript is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:97356"/>
          <criterion comment="systemtap-server is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:98039"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21490" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0607: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0607-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0607.html"/>
        <reference source="CESA" ref_id="CESA-2010:0607"/>
        <reference source="CVE" ref_id="CVE-2010-1797" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1797.html"/>
        <description>Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted CFF opcodes in embedded fonts in a PDF document, as demonstrated by JailbreakMe. NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:32.696-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:44.957-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:33.769-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="freetype is earlier than 0:2.2.1-26.el5_5" test_ref="oval:org.mitre.oval:tst:99364"/>
          <criterion comment="freetype-demos is earlier than 0:2.2.1-26.el5_5" test_ref="oval:org.mitre.oval:tst:99698"/>
          <criterion comment="freetype-devel is earlier than 0:2.2.1-26.el5_5" test_ref="oval:org.mitre.oval:tst:99619"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21486" version="250" class="patch">
      <metadata>
        <title>RHSA-2010:0153: thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0153-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0153.html"/>
        <reference source="CESA" ref_id="CESA-2010:0153"/>
        <reference source="CVE" ref_id="CVE-2009-0689" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0689.html"/>
        <reference source="CVE" ref_id="CVE-2009-1571" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1571.html"/>
        <reference source="CVE" ref_id="CVE-2009-2462" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2462.html"/>
        <reference source="CVE" ref_id="CVE-2009-2463" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2463.html"/>
        <reference source="CVE" ref_id="CVE-2009-2466" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2466.html"/>
        <reference source="CVE" ref_id="CVE-2009-2470" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2470.html"/>
        <reference source="CVE" ref_id="CVE-2009-3072" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3072.html"/>
        <reference source="CVE" ref_id="CVE-2009-3075" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3075.html"/>
        <reference source="CVE" ref_id="CVE-2009-3076" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3076.html"/>
        <reference source="CVE" ref_id="CVE-2009-3077" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3077.html"/>
        <reference source="CVE" ref_id="CVE-2009-3274" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3274.html"/>
        <reference source="CVE" ref_id="CVE-2009-3376" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3376.html"/>
        <reference source="CVE" ref_id="CVE-2009-3380" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3380.html"/>
        <reference source="CVE" ref_id="CVE-2009-3384" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3384.html"/>
        <reference source="CVE" ref_id="CVE-2009-3979" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3979.html"/>
        <reference source="CVE" ref_id="CVE-2010-0159" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0159.html"/>
        <reference source="CVE" ref_id="CVE-2010-0163" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0163.html"/>
        <reference source="CVE" ref_id="CVE-2010-0169" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0169.html"/>
        <reference source="CVE" ref_id="CVE-2010-0171" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0171.html"/>
        <description>Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allow remote attackers to perform cross-origin keystroke capture, and possibly conduct cross-site scripting (XSS) attacks, by using the addEventListener and setTimeout functions in conjunction with a wrapped object.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-3736.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:18.795-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:44.332-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:32.964-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-2.el5_4" test_ref="oval:org.mitre.oval:tst:99127"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21485" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0144: cpio security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>cpio</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0144-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0144.html"/>
        <reference source="CESA" ref_id="CESA-2010:0144"/>
        <reference source="CVE" ref_id="CVE-2007-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4476.html"/>
        <reference source="CVE" ref_id="CVE-2010-0624" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0624.html"/>
        <description>Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:20.401-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:44.245-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:32.824-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="cpio is earlier than 0:2.6-23.el5_4.1" test_ref="oval:org.mitre.oval:tst:98299"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21483" version="81" class="patch">
      <metadata>
        <title>RHSA-2011:1219: samba security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1219-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1219.html"/>
        <reference source="CESA" ref_id="CESA-2011:1219"/>
        <reference source="CVE" ref_id="CVE-2010-0547" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0547.html"/>
        <reference source="CVE" ref_id="CVE-2010-0787" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0787.html"/>
        <reference source="CVE" ref_id="CVE-2011-1678" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1678.html"/>
        <reference source="CVE" ref_id="CVE-2011-2522" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2522.html"/>
        <reference source="CVE" ref_id="CVE-2011-2694" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2694.html"/>
        <reference source="CVE" ref_id="CVE-2011-3585" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3585.html"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:04.381-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:44.069-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:32.558-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libsmbclient is earlier than 0:3.0.33-3.29.el5_7.4" test_ref="oval:org.mitre.oval:tst:98211"/>
          <criterion comment="samba-client is earlier than 0:3.0.33-3.29.el5_7.4" test_ref="oval:org.mitre.oval:tst:97964"/>
          <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.29.el5_7.4" test_ref="oval:org.mitre.oval:tst:97651"/>
          <criterion comment="samba-common is earlier than 0:3.0.33-3.29.el5_7.4" test_ref="oval:org.mitre.oval:tst:98417"/>
          <criterion comment="samba is earlier than 0:3.0.33-3.29.el5_7.4" test_ref="oval:org.mitre.oval:tst:98181"/>
          <criterion comment="samba-swat is earlier than 0:3.0.33-3.29.el5_7.4" test_ref="oval:org.mitre.oval:tst:98179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21479" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0180: pango security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>evolution28-pango</product>
          <product>pango</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0180-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0180.html"/>
        <reference source="CVE" ref_id="CVE-2011-0020" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0020.html"/>
        <description>Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file, related to the glyph box for an FT_Bitmap object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:38.850-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:43.846-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:32.267-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21479 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:23.943-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:06.479-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="pango-devel is earlier than 0:1.14.9-8.el5_6.2" test_ref="oval:org.mitre.oval:tst:137637"/>
            <criterion comment="pango is earlier than 0:1.14.9-8.el5_6.2" test_ref="oval:org.mitre.oval:tst:137822"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="pango is earlier than 0:1.28.1-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:97231"/>
            <criterion comment="pango-debuginfo is earlier than 0:1.28.1-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:137760"/>
            <criterion comment="pango-devel is earlier than 0:1.28.1-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:97059"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21474" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0411: openoffice.org security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openoffice.org</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0411-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0411.html"/>
        <reference source="CESA" ref_id="CESA-2012:0411"/>
        <reference source="CVE" ref_id="CVE-2012-0037" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0037.html"/>
        <description>Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:59.487-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:43.442-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:31.759-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openoffice.org-langpack-de is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92900"/>
          <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92844"/>
          <criterion comment="openoffice.org-javafilter is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93228"/>
          <criterion comment="openoffice.org-testtools is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93149"/>
          <criterion comment="openoffice.org-writer is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92725"/>
          <criterion comment="openoffice.org-langpack-ar is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93164"/>
          <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93342"/>
          <criterion comment="openoffice.org-pyuno is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92155"/>
          <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93101"/>
          <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93060"/>
          <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93132"/>
          <criterion comment="openoffice.org-ure is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93092"/>
          <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93251"/>
          <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93049"/>
          <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92323"/>
          <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92591"/>
          <criterion comment="openoffice.org-sdk is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92658"/>
          <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92726"/>
          <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92587"/>
          <criterion comment="openoffice.org-langpack-sv is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93217"/>
          <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93113"/>
          <criterion comment="openoffice.org-base is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92807"/>
          <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93172"/>
          <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92762"/>
          <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92752"/>
          <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92655"/>
          <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92898"/>
          <criterion comment="openoffice.org-langpack-fr is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93222"/>
          <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93001"/>
          <criterion comment="openoffice.org-langpack-it is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93289"/>
          <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93117"/>
          <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93321"/>
          <criterion comment="openoffice.org-math is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93152"/>
          <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93108"/>
          <criterion comment="openoffice.org-impress is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92842"/>
          <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92813"/>
          <criterion comment="openoffice.org-graphicfilter is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93079"/>
          <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92653"/>
          <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93330"/>
          <criterion comment="openoffice.org-sdk-doc is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92736"/>
          <criterion comment="openoffice.org-draw is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93277"/>
          <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92998"/>
          <criterion comment="openoffice.org-langpack-ru is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93093"/>
          <criterion comment="openoffice.org-headless is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92758"/>
          <criterion comment="openoffice.org-langpack-bn is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92541"/>
          <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92664"/>
          <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93099"/>
          <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93283"/>
          <criterion comment="openoffice.org-langpack-nl is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93073"/>
          <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93273"/>
          <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93312"/>
          <criterion comment="openoffice.org-xsltfilter is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92487"/>
          <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93030"/>
          <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92826"/>
          <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93141"/>
          <criterion comment="openoffice.org-core is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93052"/>
          <criterion comment="openoffice.org-calc is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92343"/>
          <criterion comment="openoffice.org is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93139"/>
          <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92647"/>
          <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92717"/>
          <criterion comment="openoffice.org-emailmerge is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93115"/>
          <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92946"/>
          <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92293"/>
          <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93221"/>
          <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92920"/>
          <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92977"/>
          <criterion comment="openoffice.org-langpack-ur is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93083"/>
          <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92883"/>
          <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93329"/>
          <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93263"/>
          <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92549"/>
          <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93086"/>
          <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93173"/>
          <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93184"/>
          <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93317"/>
          <criterion comment="openoffice.org-langpack-es is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92702"/>
          <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:92991"/>
          <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:93239"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21471" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0677: postgresql security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0677-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0677.html"/>
        <reference source="CESA" ref_id="CESA-2012:0677"/>
        <reference source="CVE" ref_id="CVE-2012-0866" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0866.html"/>
        <reference source="CVE" ref_id="CVE-2012-0868" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0868.html"/>
        <description>CRLF injection vulnerability in pg_dump in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows user-assisted remote attackers to execute arbitrary SQL commands via a crafted file containing object names with newlines, which are inserted into an SQL script that is used when the database is restored.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:57.824-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:43.140-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:31.276-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="postgresql-libs is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:93443"/>
          <criterion comment="postgresql-pl is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:93309"/>
          <criterion comment="postgresql-python is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:92543"/>
          <criterion comment="postgresql-tcl is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:92959"/>
          <criterion comment="postgresql-docs is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:93219"/>
          <criterion comment="postgresql-devel is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:93486"/>
          <criterion comment="postgresql-test is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:93420"/>
          <criterion comment="postgresql-contrib is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:93232"/>
          <criterion comment="postgresql-server is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:93325"/>
          <criterion comment="postgresql is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:92516"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21464" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1235: kvm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1235-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1235.html"/>
        <reference source="CESA" ref_id="CESA-2012:1235"/>
        <reference source="CVE" ref_id="CVE-2012-3515" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3515.html"/>
        <description>Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:53.777-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:43.057-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:31.140-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="kmod-kvm-debug is earlier than 0:83-249.el5_8.5" test_ref="oval:org.mitre.oval:tst:94306"/>
            <criterion comment="kvm is earlier than 0:83-249.el5_8.5" test_ref="oval:org.mitre.oval:tst:94465"/>
            <criterion comment="kmod-kvm is earlier than 0:83-249.el5_8.5" test_ref="oval:org.mitre.oval:tst:93517"/>
            <criterion comment="kvm-qemu-img is earlier than 0:83-249.el5_8.5" test_ref="oval:org.mitre.oval:tst:94451"/>
            <criterion comment="kvm-tools is earlier than 0:83-249.el5_8.5" test_ref="oval:org.mitre.oval:tst:94071"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="kmod-kvm-debug is earlier than 0:83-249.el5.centos.5" test_ref="oval:org.mitre.oval:tst:94960"/>
            <criterion comment="kvm is earlier than 0:83-249.el5.centos.5" test_ref="oval:org.mitre.oval:tst:94735"/>
            <criterion comment="kmod-kvm is earlier than 0:83-249.el5.centos.5" test_ref="oval:org.mitre.oval:tst:95023"/>
            <criterion comment="kvm-qemu-img is earlier than 0:83-249.el5.centos.5" test_ref="oval:org.mitre.oval:tst:94928"/>
            <criterion comment="kvm-tools is earlier than 0:83-249.el5.centos.5" test_ref="oval:org.mitre.oval:tst:94997"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21461" version="185" class="patch">
      <metadata>
        <title>RHSA-2012:0467: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0467-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0467.html"/>
        <reference source="CESA" ref_id="CESA-2012:0467"/>
        <reference source="CVE" ref_id="CVE-2012-1126" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1126.html"/>
        <reference source="CVE" ref_id="CVE-2012-1127" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1127.html"/>
        <reference source="CVE" ref_id="CVE-2012-1130" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1130.html"/>
        <reference source="CVE" ref_id="CVE-2012-1131" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1131.html"/>
        <reference source="CVE" ref_id="CVE-2012-1132" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1132.html"/>
        <reference source="CVE" ref_id="CVE-2012-1134" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1134.html"/>
        <reference source="CVE" ref_id="CVE-2012-1136" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1136.html"/>
        <reference source="CVE" ref_id="CVE-2012-1137" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1137.html"/>
        <reference source="CVE" ref_id="CVE-2012-1139" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1139.html"/>
        <reference source="CVE" ref_id="CVE-2012-1140" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1140.html"/>
        <reference source="CVE" ref_id="CVE-2012-1141" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1141.html"/>
        <reference source="CVE" ref_id="CVE-2012-1142" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1142.html"/>
        <reference source="CVE" ref_id="CVE-2012-1143" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1143.html"/>
        <reference source="CVE" ref_id="CVE-2012-1144" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1144.html"/>
        <description>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via a crafted TrueType font.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:03.305-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:42.752-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:30.533-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:92695"/>
            <criterion comment="freetype is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:93043"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:93350"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:93242"/>
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:93348"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:93238"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21460" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0676: kvm security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0676-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0676.html"/>
        <reference source="CESA" ref_id="CESA-2012:0676"/>
        <reference source="CVE" ref_id="CVE-2012-1601" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1601.html"/>
        <reference source="CVE" ref_id="CVE-2012-2121" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2121.html"/>
        <description>The KVM implementation in the Linux kernel before 3.3.4 does not properly manage the relationships between memory slots and the iommu, which allows guest OS users to cause a denial of service (memory leak and host OS crash) by leveraging administrative access to the guest OS to conduct hotunplug and hotplug operations on devices.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:32.267-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:42.656-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:30.388-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="kmod-kvm is earlier than 0:83-249.el5_8.4" test_ref="oval:org.mitre.oval:tst:93205"/>
            <criterion comment="kvm-tools is earlier than 0:83-249.el5_8.4" test_ref="oval:org.mitre.oval:tst:93211"/>
            <criterion comment="kvm-qemu-img is earlier than 0:83-249.el5_8.4" test_ref="oval:org.mitre.oval:tst:93453"/>
            <criterion comment="kmod-kvm-debug is earlier than 0:83-249.el5_8.4" test_ref="oval:org.mitre.oval:tst:93191"/>
            <criterion comment="kvm is earlier than 0:83-249.el5_8.4" test_ref="oval:org.mitre.oval:tst:93297"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="kmod-kvm is earlier than 0:83-249.el5.centos.4" test_ref="oval:org.mitre.oval:tst:94665"/>
            <criterion comment="kvm-tools is earlier than 0:83-249.el5.centos.4" test_ref="oval:org.mitre.oval:tst:94978"/>
            <criterion comment="kvm-qemu-img is earlier than 0:83-249.el5.centos.4" test_ref="oval:org.mitre.oval:tst:94769"/>
            <criterion comment="kmod-kvm-debug is earlier than 0:83-249.el5.centos.4" test_ref="oval:org.mitre.oval:tst:94623"/>
            <criterion comment="kvm is earlier than 0:83-249.el5.centos.4" test_ref="oval:org.mitre.oval:tst:94987"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21457" version="94" class="patch">
      <metadata>
        <title>RHSA-2010:0682: thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0682-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0682.html"/>
        <reference source="CESA" ref_id="CESA-2010:0682"/>
        <reference source="CVE" ref_id="CVE-2010-2760" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2760.html"/>
        <reference source="CVE" ref_id="CVE-2010-2765" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2765.html"/>
        <reference source="CVE" ref_id="CVE-2010-2767" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2767.html"/>
        <reference source="CVE" ref_id="CVE-2010-2768" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2768.html"/>
        <reference source="CVE" ref_id="CVE-2010-3167" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3167.html"/>
        <reference source="CVE" ref_id="CVE-2010-3168" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3168.html"/>
        <reference source="CVE" ref_id="CVE-2010-3169" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3169.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:35.772-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:42.314-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:29.890-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-8.el5" test_ref="oval:org.mitre.oval:tst:99161"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21447" version="122" class="patch">
      <metadata>
        <title>RHSA-2012:1238: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1238-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1238.html"/>
        <reference source="CVE" ref_id="CVE-2012-0551" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0551.html"/>
        <reference source="CVE" ref_id="CVE-2012-1713" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1713.html"/>
        <reference source="CVE" ref_id="CVE-2012-1716" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1716.html"/>
        <reference source="CVE" ref_id="CVE-2012-1717" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1717.html"/>
        <reference source="CVE" ref_id="CVE-2012-1718" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1718.html"/>
        <reference source="CVE" ref_id="CVE-2012-1719" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1719.html"/>
        <reference source="CVE" ref_id="CVE-2012-1721" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1721.html"/>
        <reference source="CVE" ref_id="CVE-2012-1722" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1722.html"/>
        <reference source="CVE" ref_id="CVE-2012-1725" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1725.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, and 5 update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:18.757-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:41.796-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:29.107-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21447 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:15.504-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:05.524-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137558"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137867"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137154"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137790"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137919"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137905"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137773"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137674"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94510"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94179"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94059"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94517"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:93561"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94187"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94371"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21435" version="174" class="patch">
      <metadata>
        <title>RHSA-2011:0885: firefox security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0885-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0885.html"/>
        <reference source="CVE" ref_id="CVE-2011-0083" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0083.html"/>
        <reference source="CVE" ref_id="CVE-2011-0085" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0085.html"/>
        <reference source="CVE" ref_id="CVE-2011-2362" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2362.html"/>
        <reference source="CVE" ref_id="CVE-2011-2363" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2363.html"/>
        <reference source="CVE" ref_id="CVE-2011-2364" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2364.html"/>
        <reference source="CVE" ref_id="CVE-2011-2365" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2365.html"/>
        <reference source="CVE" ref_id="CVE-2011-2371" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2371.html"/>
        <reference source="CVE" ref_id="CVE-2011-2373" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2373.html"/>
        <reference source="CVE" ref_id="CVE-2011-2374" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2374.html"/>
        <reference source="CVE" ref_id="CVE-2011-2375" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2375.html"/>
        <reference source="CVE" ref_id="CVE-2011-2376" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2376.html"/>
        <reference source="CVE" ref_id="CVE-2011-2377" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2377.html"/>
        <reference source="CVE" ref_id="CVE-2011-2605" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2605.html"/>
        <reference source="CESA-2011:0885" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-June/017621.html" ref_id="CESA-2011:0885-CentOS 5"/>
        <description>CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/cookie/nsCookieService.cpp in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allows remote attackers to bypass intended access restrictions via a string containing a \n (newline) character, which is not properly handled in a JavaScript "document.cookie =" expression, a different vulnerability than CVE-2011-2374.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:59.136-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:41.118-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:28.283-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21435 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:15.027-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:03.999-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.18-2.el5_6" test_ref="oval:org.mitre.oval:tst:137844"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.18-2.el5_6" test_ref="oval:org.mitre.oval:tst:137543"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:3.6.18-1.el5_6" test_ref="oval:org.mitre.oval:tst:137886"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:3.6.18-1.el6_1" test_ref="oval:org.mitre.oval:tst:98128"/>
            <criterion comment="firefox-debuginfo is earlier than 0:3.6.18-1.el6_1" test_ref="oval:org.mitre.oval:tst:137646"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.18-2.el6_1" test_ref="oval:org.mitre.oval:tst:98209"/>
            <criterion comment="xulrunner-debuginfo is earlier than 0:1.9.2.18-2.el6_1" test_ref="oval:org.mitre.oval:tst:137812"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.18-2.el6_1" test_ref="oval:org.mitre.oval:tst:98234"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:3.6.18-1.el5.centos" test_ref="oval:org.mitre.oval:tst:137643"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21434" version="315" class="patch">
      <metadata>
        <title>RHSA-2012:1210: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1210-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1210.html"/>
        <reference source="CESA" ref_id="CESA-2012:1210"/>
        <reference source="CVE" ref_id="CVE-2012-1970" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1970.html"/>
        <reference source="CVE" ref_id="CVE-2012-1972" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1972.html"/>
        <reference source="CVE" ref_id="CVE-2012-1973" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1973.html"/>
        <reference source="CVE" ref_id="CVE-2012-1974" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1974.html"/>
        <reference source="CVE" ref_id="CVE-2012-1975" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1975.html"/>
        <reference source="CVE" ref_id="CVE-2012-1976" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1976.html"/>
        <reference source="CVE" ref_id="CVE-2012-3956" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3956.html"/>
        <reference source="CVE" ref_id="CVE-2012-3957" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3957.html"/>
        <reference source="CVE" ref_id="CVE-2012-3958" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3958.html"/>
        <reference source="CVE" ref_id="CVE-2012-3959" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3959.html"/>
        <reference source="CVE" ref_id="CVE-2012-3960" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3960.html"/>
        <reference source="CVE" ref_id="CVE-2012-3961" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3961.html"/>
        <reference source="CVE" ref_id="CVE-2012-3962" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3962.html"/>
        <reference source="CVE" ref_id="CVE-2012-3963" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3963.html"/>
        <reference source="CVE" ref_id="CVE-2012-3964" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3964.html"/>
        <reference source="CVE" ref_id="CVE-2012-3966" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3966.html"/>
        <reference source="CVE" ref_id="CVE-2012-3967" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3967.html"/>
        <reference source="CVE" ref_id="CVE-2012-3968" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3968.html"/>
        <reference source="CVE" ref_id="CVE-2012-3969" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3969.html"/>
        <reference source="CVE" ref_id="CVE-2012-3970" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3970.html"/>
        <reference source="CVE" ref_id="CVE-2012-3972" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3972.html"/>
        <reference source="CVE" ref_id="CVE-2012-3976" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3976.html"/>
        <reference source="CVE" ref_id="CVE-2012-3978" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3978.html"/>
        <reference source="CVE" ref_id="CVE-2012-3980" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3980.html"/>
        <description>The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that injects this code and triggers an eval operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:45.777-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:40.650-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:27.610-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.7-2.el5_8" test_ref="oval:org.mitre.oval:tst:94093"/>
            <criterion comment="xulrunner is earlier than 0:10.0.7-2.el5_8" test_ref="oval:org.mitre.oval:tst:93780"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:10.0.7-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94361"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:10.0.7-1.el5_8" test_ref="oval:org.mitre.oval:tst:93506"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:94434"/>
            <criterion comment="xulrunner is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:94337"/>
            <criterion comment="firefox is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:94474"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.7-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94875"/>
            <criterion comment="xulrunner is earlier than 0:10.0.7-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94933"/>
            <criterion comment="firefox is earlier than 0:10.0.7-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94509"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21429" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1122: bind97 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1122-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1122.html"/>
        <reference source="CESA" ref_id="CESA-2012:1122"/>
        <reference source="CVE" ref_id="CVE-2012-3817" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3817.html"/>
        <description>ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:25.918-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:39.941-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:26.585-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="bind97-chroot is earlier than 32:9.7.0-10.P2.el5_8.2" test_ref="oval:org.mitre.oval:tst:93467"/>
          <criterion comment="bind97-devel is earlier than 32:9.7.0-10.P2.el5_8.2" test_ref="oval:org.mitre.oval:tst:93902"/>
          <criterion comment="bind97-utils is earlier than 32:9.7.0-10.P2.el5_8.2" test_ref="oval:org.mitre.oval:tst:93804"/>
          <criterion comment="bind97 is earlier than 32:9.7.0-10.P2.el5_8.2" test_ref="oval:org.mitre.oval:tst:93788"/>
          <criterion comment="bind97-libs is earlier than 32:9.7.0-10.P2.el5_8.2" test_ref="oval:org.mitre.oval:tst:93555"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21427" version="133" class="patch">
      <metadata>
        <title>RHSA-2012:0710: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0710-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0710.html"/>
        <reference source="CESA" ref_id="CESA-2012:0710"/>
        <reference source="CVE" ref_id="CVE-2011-3101" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3101.html"/>
        <reference source="CVE" ref_id="CVE-2012-1937" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1937.html"/>
        <reference source="CVE" ref_id="CVE-2012-1938" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1938.html"/>
        <reference source="CVE" ref_id="CVE-2012-1939" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1939.html"/>
        <reference source="CVE" ref_id="CVE-2012-1940" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1940.html"/>
        <reference source="CVE" ref_id="CVE-2012-1941" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1941.html"/>
        <reference source="CVE" ref_id="CVE-2012-1944" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1944.html"/>
        <reference source="CVE" ref_id="CVE-2012-1945" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1945.html"/>
        <reference source="CVE" ref_id="CVE-2012-1946" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1946.html"/>
        <reference source="CVE" ref_id="CVE-2012-1947" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1947.html"/>
        <description>Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:58.231-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:39.634-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:26.382-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.5-1.el5_8" test_ref="oval:org.mitre.oval:tst:93853"/>
            <criterion comment="xulrunner is earlier than 0:10.0.5-1.el5_8" test_ref="oval:org.mitre.oval:tst:93792"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:10.0.5-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94639"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:10.0.5-1.el5_8" test_ref="oval:org.mitre.oval:tst:93625"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.5-1.el6_2" test_ref="oval:org.mitre.oval:tst:93513"/>
            <criterion comment="xulrunner is earlier than 0:10.0.5-1.el6_2" test_ref="oval:org.mitre.oval:tst:93267"/>
            <criterion comment="firefox is earlier than 0:10.0.5-1.el6_2" test_ref="oval:org.mitre.oval:tst:93805"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.5-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94740"/>
            <criterion comment="xulrunner is earlier than 0:10.0.5-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94967"/>
            <criterion comment="firefox is earlier than 0:10.0.5-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94601"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21426" version="7" class="patch">
      <metadata>
        <title>RHSA-2011:0373: firefox security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0373-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0373.html"/>
        <reference source="CESA-2011:0373" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017409.html" ref_id="CESA-2011:0373-CentOS 5"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

This erratum blacklists a small number of HTTPS certificates. (BZ#689430)

All Firefox users should upgrade to these updated packages, which contain
a backported patch. After installing the update, Firefox must be restarted
for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:32.183-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:39.594-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:26.289-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21426 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:42.298-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:38.750-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21426 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:28.683-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:03.739-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.15-2.el5_6" test_ref="oval:org.mitre.oval:tst:137088"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.15-2.el5_6" test_ref="oval:org.mitre.oval:tst:137891"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner is earlier than 0:1.9.2.15-2.el6_0" test_ref="oval:org.mitre.oval:tst:97163"/>
            <criterion comment="xulrunner-debuginfo is earlier than 0:1.9.2.15-2.el6_0" test_ref="oval:org.mitre.oval:tst:137776"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.15-2.el6_0" test_ref="oval:org.mitre.oval:tst:97565"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21422" version="198" class="patch">
      <metadata>
        <title>RHSA-2012:1385: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1385-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1385.html"/>
        <reference source="CESA" ref_id="CESA-2012:1385"/>
        <reference source="CVE" ref_id="CVE-2012-3216" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3216.html"/>
        <reference source="CVE" ref_id="CVE-2012-4416" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4416.html"/>
        <reference source="CVE" ref_id="CVE-2012-5068" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5068.html"/>
        <reference source="CVE" ref_id="CVE-2012-5069" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5069.html"/>
        <reference source="CVE" ref_id="CVE-2012-5071" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5071.html"/>
        <reference source="CVE" ref_id="CVE-2012-5072" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5072.html"/>
        <reference source="CVE" ref_id="CVE-2012-5073" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5073.html"/>
        <reference source="CVE" ref_id="CVE-2012-5075" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5075.html"/>
        <reference source="CVE" ref_id="CVE-2012-5077" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5077.html"/>
        <reference source="CVE" ref_id="CVE-2012-5079" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5079.html"/>
        <reference source="CVE" ref_id="CVE-2012-5081" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5081.html"/>
        <reference source="CVE" ref_id="CVE-2012-5084" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5084.html"/>
        <reference source="CVE" ref_id="CVE-2012-5085" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5085.html"/>
        <reference source="CVE" ref_id="CVE-2012-5086" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5086.html"/>
        <reference source="CVE" ref_id="CVE-2012-5089" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5089.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JMX.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:52.608-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:39.197-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:25.764-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.28.1.10.10.el5_8" test_ref="oval:org.mitre.oval:tst:94556"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.28.1.10.10.el5_8" test_ref="oval:org.mitre.oval:tst:94828"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.28.1.10.10.el5_8" test_ref="oval:org.mitre.oval:tst:94694"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.28.1.10.10.el5_8" test_ref="oval:org.mitre.oval:tst:94658"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.28.1.10.10.el5_8" test_ref="oval:org.mitre.oval:tst:94691"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21420" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0336: tomcat5 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>tomcat5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0336-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0336.html"/>
        <reference source="CESA" ref_id="CESA-2011:0336"/>
        <reference source="CVE" ref_id="CVE-2010-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4476.html"/>
        <description>The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:53.023-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:39.035-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:25.471-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:97410"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:97277"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:97592"/>
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:97354"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:97388"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:97167"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:97579"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:97449"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:97512"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:97590"/>
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:97199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21419" version="42" class="patch">
      <metadata>
        <title>RHSA-2010:0109: mysql security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0109-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0109.html"/>
        <reference source="CESA" ref_id="CESA-2010:0109"/>
        <reference source="CVE" ref_id="CVE-2009-4019" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4019.html"/>
        <reference source="CVE" ref_id="CVE-2009-4028" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4028.html"/>
        <reference source="CVE" ref_id="CVE-2009-4030" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4030.html"/>
        <description>MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:05.322-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:38.920-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:25.203-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mysql-test is earlier than 0:5.0.77-4.el5_4.2" test_ref="oval:org.mitre.oval:tst:99249"/>
          <criterion comment="mysql is earlier than 0:5.0.77-4.el5_4.2" test_ref="oval:org.mitre.oval:tst:98799"/>
          <criterion comment="mysql-server is earlier than 0:5.0.77-4.el5_4.2" test_ref="oval:org.mitre.oval:tst:98702"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.77-4.el5_4.2" test_ref="oval:org.mitre.oval:tst:99231"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.77-4.el5_4.2" test_ref="oval:org.mitre.oval:tst:99247"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21417" version="133" class="patch">
      <metadata>
        <title>RHSA-2012:0715: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0715-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0715.html"/>
        <reference source="CESA" ref_id="CESA-2012:0715"/>
        <reference source="CVE" ref_id="CVE-2011-3101" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3101.html"/>
        <reference source="CVE" ref_id="CVE-2012-1937" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1937.html"/>
        <reference source="CVE" ref_id="CVE-2012-1938" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1938.html"/>
        <reference source="CVE" ref_id="CVE-2012-1939" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1939.html"/>
        <reference source="CVE" ref_id="CVE-2012-1940" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1940.html"/>
        <reference source="CVE" ref_id="CVE-2012-1941" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1941.html"/>
        <reference source="CVE" ref_id="CVE-2012-1944" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1944.html"/>
        <reference source="CVE" ref_id="CVE-2012-1945" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1945.html"/>
        <reference source="CVE" ref_id="CVE-2012-1946" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1946.html"/>
        <reference source="CVE" ref_id="CVE-2012-1947" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1947.html"/>
        <description>Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:02.278-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:38.663-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:24.704-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.5-2.el5_8" test_ref="oval:org.mitre.oval:tst:93540"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.5-2.el5.centos" test_ref="oval:org.mitre.oval:tst:94763"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.5-2.el6_2" test_ref="oval:org.mitre.oval:tst:93405"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.5-2.el6.centos" test_ref="oval:org.mitre.oval:tst:95039"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21416" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0547: php53 security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>php53</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0547-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0547.html"/>
        <reference source="CESA" ref_id="CESA-2012:0547"/>
        <reference source="CVE" ref_id="CVE-2012-1823" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1823.html"/>
        <description>sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:55.528-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:38.564-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:24.372-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:93337"/>
          <criterion comment="php53-gd is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:93415"/>
          <criterion comment="php53 is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:93084"/>
          <criterion comment="php53-imap is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:93365"/>
          <criterion comment="php53-pgsql is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:93386"/>
          <criterion comment="php53-process is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:93194"/>
          <criterion comment="php53-ldap is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:92816"/>
          <criterion comment="php53-soap is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:93390"/>
          <criterion comment="php53-cli is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:93161"/>
          <criterion comment="php53-bcmath is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:92969"/>
          <criterion comment="php53-xml is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:92466"/>
          <criterion comment="php53-pdo is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:93109"/>
          <criterion comment="php53-snmp is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:92623"/>
          <criterion comment="php53-mbstring is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:93244"/>
          <criterion comment="php53-odbc is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:92974"/>
          <criterion comment="php53-mysql is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:93138"/>
          <criterion comment="php53-pspell is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:93226"/>
          <criterion comment="php53-common is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:93098"/>
          <criterion comment="php53-intl is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:93428"/>
          <criterion comment="php53-devel is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:92885"/>
          <criterion comment="php53-dba is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:93389"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21415" version="289" class="patch">
      <metadata>
        <title>RHSA-2010:0383: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0383-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0383.html"/>
        <reference source="CVE" ref_id="CVE-2010-0084" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0084.html"/>
        <reference source="CVE" ref_id="CVE-2010-0085" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0085.html"/>
        <reference source="CVE" ref_id="CVE-2010-0087" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0087.html"/>
        <reference source="CVE" ref_id="CVE-2010-0088" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0088.html"/>
        <reference source="CVE" ref_id="CVE-2010-0089" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0089.html"/>
        <reference source="CVE" ref_id="CVE-2010-0090" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0090.html"/>
        <reference source="CVE" ref_id="CVE-2010-0091" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0091.html"/>
        <reference source="CVE" ref_id="CVE-2010-0092" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0092.html"/>
        <reference source="CVE" ref_id="CVE-2010-0094" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0094.html"/>
        <reference source="CVE" ref_id="CVE-2010-0095" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0095.html"/>
        <reference source="CVE" ref_id="CVE-2010-0837" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0837.html"/>
        <reference source="CVE" ref_id="CVE-2010-0838" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0838.html"/>
        <reference source="CVE" ref_id="CVE-2010-0839" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0839.html"/>
        <reference source="CVE" ref_id="CVE-2010-0840" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0840.html"/>
        <reference source="CVE" ref_id="CVE-2010-0841" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0841.html"/>
        <reference source="CVE" ref_id="CVE-2010-0842" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0842.html"/>
        <reference source="CVE" ref_id="CVE-2010-0843" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0843.html"/>
        <reference source="CVE" ref_id="CVE-2010-0844" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0844.html"/>
        <reference source="CVE" ref_id="CVE-2010-0846" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0846.html"/>
        <reference source="CVE" ref_id="CVE-2010-0847" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0847.html"/>
        <reference source="CVE" ref_id="CVE-2010-0848" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0848.html"/>
        <reference source="CVE" ref_id="CVE-2010-0849" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0849.html"/>
        <description>Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow in a decoding routine used by the JPEGImageDecoderImpl interface, which allows code execution via a crafted JPEG image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:36.617-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:38.147-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:23.638-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.8-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99250"/>
          <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.8-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99334"/>
          <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.8-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99233"/>
          <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.8-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99359"/>
          <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.8-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99348"/>
          <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.8-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99372"/>
          <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.8-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99394"/>
          <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.8-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99287"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21413" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0307: util-linux security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>util-linux</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0307-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0307.html"/>
        <reference source="CVE" ref_id="CVE-2011-1675" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1675.html"/>
        <reference source="CVE" ref_id="CVE-2011-1677" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1677.html"/>
        <description>mount in util-linux 2.19 and earlier does not remove the /etc/mtab~ lock file after a failed attempt to add a mount entry, which has unspecified impact and local attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:21.010-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:38.073-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:23.531-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="util-linux is earlier than 0:2.13-0.59.el5" test_ref="oval:org.mitre.oval:tst:92911"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21412" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0474: tomcat5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>tomcat5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0474-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0474.html"/>
        <reference source="CESA" ref_id="CESA-2012:0474"/>
        <reference source="CVE" ref_id="CVE-2011-4858" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4858.html"/>
        <reference source="CVE" ref_id="CVE-2012-0022" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0022.html"/>
        <description>Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:24.173-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:37.968-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:23.356-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:92873"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:93095"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:93256"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:92976"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:92718"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:92387"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:93344"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:92972"/>
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:92966"/>
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:93199"/>
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:93174"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21408" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0136: libvorbis security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libvorbis</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0136-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0136.html"/>
        <reference source="CESA" ref_id="CESA-2012:0136"/>
        <reference source="CVE" ref_id="CVE-2012-0444" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0444.html"/>
        <description>Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:49.477-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:37.600-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:22.750-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libvorbis is earlier than 1:1.2.3-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:92836"/>
            <criterion comment="libvorbis-devel is earlier than 1:1.2.3-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:92918"/>
            <criterion comment="libvorbis-devel-docs is earlier than 1:1.2.3-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:93040"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libvorbis is earlier than 1:1.1.2-3.el5_7.6" test_ref="oval:org.mitre.oval:tst:92964"/>
            <criterion comment="libvorbis-devel is earlier than 1:1.1.2-3.el5_7.6" test_ref="oval:org.mitre.oval:tst:92940"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21407" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0434: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0434-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0434.html"/>
        <reference source="CVE" ref_id="CVE-2012-0773" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0773.html"/>
        <description>The NetStream class in Adobe Flash Player before 10.3.183.18 and 11.x before 11.2.202.228 on Windows, Mac OS X, and Linux; Flash Player before 10.3.183.18 and 11.x before 11.2.202.223 on Solaris; Flash Player before 11.1.111.8 on Android 2.x and 3.x; and AIR before 3.2.0.2070 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:09.517-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:37.529-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:22.651-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.18-1.el5" test_ref="oval:org.mitre.oval:tst:92747"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.18-1.el6" test_ref="oval:org.mitre.oval:tst:92529"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21404" version="161" class="patch">
      <metadata>
        <title>RHSA-2012:0514: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0514-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0514.html"/>
        <reference source="CVE" ref_id="CVE-2011-3563" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3563.html"/>
        <reference source="CVE" ref_id="CVE-2011-5035" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-5035.html"/>
        <reference source="CVE" ref_id="CVE-2012-0497" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0497.html"/>
        <reference source="CVE" ref_id="CVE-2012-0498" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0498.html"/>
        <reference source="CVE" ref_id="CVE-2012-0499" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0499.html"/>
        <reference source="CVE" ref_id="CVE-2012-0500" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0500.html"/>
        <reference source="CVE" ref_id="CVE-2012-0501" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0501.html"/>
        <reference source="CVE" ref_id="CVE-2012-0502" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0502.html"/>
        <reference source="CVE" ref_id="CVE-2012-0503" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0503.html"/>
        <reference source="CVE" ref_id="CVE-2012-0505" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0505.html"/>
        <reference source="CVE" ref_id="CVE-2012-0506" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0506.html"/>
        <reference source="CVE" ref_id="CVE-2012-0507" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0507.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency.  NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions.  NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:44.821-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:37.214-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:22.230-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21404 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:28.964-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:02.570-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.10.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137818"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.10.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137749"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.10.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137383"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.10.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137901"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.10.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137870"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.10.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137766"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.10.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137830"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.10.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:136938"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" test_ref="oval:org.mitre.oval:tst:92894"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" test_ref="oval:org.mitre.oval:tst:92942"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" test_ref="oval:org.mitre.oval:tst:92824"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" test_ref="oval:org.mitre.oval:tst:93358"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" test_ref="oval:org.mitre.oval:tst:93089"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" test_ref="oval:org.mitre.oval:tst:92854"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" test_ref="oval:org.mitre.oval:tst:93104"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21402" version="107" class="patch">
      <metadata>
        <title>RHSA-2012:1047: php53 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>php53</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1047-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1047.html"/>
        <reference source="CESA" ref_id="CESA-2012:1047"/>
        <reference source="CVE" ref_id="CVE-2010-2950" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2950.html"/>
        <reference source="CVE" ref_id="CVE-2011-4153" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4153.html"/>
        <reference source="CVE" ref_id="CVE-2012-0057" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0057.html"/>
        <reference source="CVE" ref_id="CVE-2012-0789" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0789.html"/>
        <reference source="CVE" ref_id="CVE-2012-1172" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1172.html"/>
        <reference source="CVE" ref_id="CVE-2012-2143" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2143.html"/>
        <reference source="CVE" ref_id="CVE-2012-2336" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2336.html"/>
        <reference source="CVE" ref_id="CVE-2012-2386" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2386.html"/>
        <description>Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP before 5.3.14 and 5.4.x before 5.4.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tar file that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:54.482-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:36.719-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:21.576-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:94132"/>
          <criterion comment="php53-odbc is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:93594"/>
          <criterion comment="php53-bcmath is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:93500"/>
          <criterion comment="php53-imap is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:93776"/>
          <criterion comment="php53-pdo is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:94077"/>
          <criterion comment="php53 is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:93165"/>
          <criterion comment="php53-mbstring is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:93991"/>
          <criterion comment="php53-intl is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:94133"/>
          <criterion comment="php53-common is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:93423"/>
          <criterion comment="php53-devel is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:94052"/>
          <criterion comment="php53-cli is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:94096"/>
          <criterion comment="php53-soap is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:94153"/>
          <criterion comment="php53-pspell is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:93446"/>
          <criterion comment="php53-dba is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:94000"/>
          <criterion comment="php53-ldap is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:93452"/>
          <criterion comment="php53-pgsql is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:93769"/>
          <criterion comment="php53-gd is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:94142"/>
          <criterion comment="php53-mysql is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:93817"/>
          <criterion comment="php53-xml is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:94065"/>
          <criterion comment="php53-snmp is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:94080"/>
          <criterion comment="php53-process is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:94053"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21401" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0675: sudo security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0675-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0675.html"/>
        <reference source="CESA" ref_id="CESA-2010:0675"/>
        <reference source="CVE" ref_id="CVE-2010-2956" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2956.html"/>
        <description>Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a "-u root" sequence.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:17.332-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:36.644-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:21.480-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="sudo is earlier than 0:1.7.2p1-8.el5_5" test_ref="oval:org.mitre.oval:tst:99501"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21398" version="161" class="patch">
      <metadata>
        <title>RHSA-2012:0508: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0508-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0508.html"/>
        <reference source="CVE" ref_id="CVE-2011-3389" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3389.html"/>
        <reference source="CVE" ref_id="CVE-2011-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3557.html"/>
        <reference source="CVE" ref_id="CVE-2011-3560" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3560.html"/>
        <reference source="CVE" ref_id="CVE-2011-3563" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3563.html"/>
        <reference source="CVE" ref_id="CVE-2012-0498" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0498.html"/>
        <reference source="CVE" ref_id="CVE-2012-0499" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0499.html"/>
        <reference source="CVE" ref_id="CVE-2012-0501" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0501.html"/>
        <reference source="CVE" ref_id="CVE-2012-0502" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0502.html"/>
        <reference source="CVE" ref_id="CVE-2012-0503" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0503.html"/>
        <reference source="CVE" ref_id="CVE-2012-0505" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0505.html"/>
        <reference source="CVE" ref_id="CVE-2012-0506" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0506.html"/>
        <reference source="CVE" ref_id="CVE-2012-0507" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0507.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency.  NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions.  NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:08.067-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:36.352-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:21.099-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21398 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:18.944-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:01.303-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137436"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.13.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137849"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137906"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137615"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137619"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137737"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137286"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137936"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:92960"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:92763"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:92405"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:93293"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:92581"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:93370"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:93022"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21396" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0466: samba3x security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>samba3x</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0466-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0466.html"/>
        <reference source="CESA" ref_id="CESA-2012:0466"/>
        <reference source="CVE" ref_id="CVE-2012-1182" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1182.html"/>
        <description>The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:43.091-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:36.227-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:20.938-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="samba3x-common is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:93187"/>
          <criterion comment="samba3x-swat is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:93096"/>
          <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:92948"/>
          <criterion comment="samba3x-client is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:92429"/>
          <criterion comment="samba3x is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:93252"/>
          <criterion comment="samba3x-winbind is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:92674"/>
          <criterion comment="samba3x-winbind-devel is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:93056"/>
          <criterion comment="samba3x-doc is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:93246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21395" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0690: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0690-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0690.html"/>
        <reference source="CESA" ref_id="CESA-2012:0690"/>
        <reference source="CVE" ref_id="CVE-2012-2136" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2136.html"/>
        <description>The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows local users to cause a denial of service (heap-based buffer overflow and system crash) or possibly gain privileges by leveraging access to a TUN/TAP device.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:00.055-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:36.125-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:20.820-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:93558"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:93198"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:93376"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:92838"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:93492"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:93127"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:93266"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:93471"/>
          <criterion comment="kernel is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:93385"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:93503"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:93547"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:93520"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21394" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0546: php security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0546-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0546.html"/>
        <reference source="CESA" ref_id="CESA-2012:0546"/>
        <reference source="CVE" ref_id="CVE-2012-1823" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1823.html"/>
        <description>sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:38.481-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:35.964-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:20.611-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php-common is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93366"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93254"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93179"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93019"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93058"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:92904"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93158"/>
            <criterion comment="php is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93223"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93201"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:92622"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93285"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93111"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:92905"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93094"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:92648"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93274"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93181"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:92791"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93077"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93407"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93408"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93422"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93416"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93142"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93282"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93403"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93426"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93193"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:92979"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93197"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:92879"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93170"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93363"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93412"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93200"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93404"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93114"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:92988"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93207"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93368"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:92434"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93070"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93229"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93157"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:92982"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21392" version="133" class="patch">
      <metadata>
        <title>RHSA-2012:0388: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0388-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0388.html"/>
        <reference source="CESA" ref_id="CESA-2012:0388"/>
        <reference source="CVE" ref_id="CVE-2012-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0451.html"/>
        <reference source="CVE" ref_id="CVE-2012-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0455.html"/>
        <reference source="CVE" ref_id="CVE-2012-0456" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0456.html"/>
        <reference source="CVE" ref_id="CVE-2012-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0457.html"/>
        <reference source="CVE" ref_id="CVE-2012-0458" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0458.html"/>
        <reference source="CVE" ref_id="CVE-2012-0459" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0459.html"/>
        <reference source="CVE" ref_id="CVE-2012-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0460.html"/>
        <reference source="CVE" ref_id="CVE-2012-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0461.html"/>
        <reference source="CVE" ref_id="CVE-2012-0462" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0462.html"/>
        <reference source="CVE" ref_id="CVE-2012-0464" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0464.html"/>
        <description>Use-after-free vulnerability in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to execute arbitrary code via vectors involving an empty argument to the array.join function in conjunction with the triggering of garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:18.266-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:35.728-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:20.288-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.3-1.el5_8" test_ref="oval:org.mitre.oval:tst:93120"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.3-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94945"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.3-1.el6_2" test_ref="oval:org.mitre.oval:tst:93140"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.3-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94449"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21391" version="81" class="patch">
      <metadata>
        <title>RHSA-2010:0040: php security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0040-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0040.html"/>
        <reference source="CESA" ref_id="CESA-2010:0040"/>
        <reference source="CVE" ref_id="CVE-2009-2687" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2687.html"/>
        <reference source="CVE" ref_id="CVE-2009-3291" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3291.html"/>
        <reference source="CVE" ref_id="CVE-2009-3292" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3292.html"/>
        <reference source="CVE" ref_id="CVE-2009-3546" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3546.html"/>
        <reference source="CVE" ref_id="CVE-2009-4017" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4017.html"/>
        <reference source="CVE" ref_id="CVE-2009-4142" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4142.html"/>
        <description>The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:08.354-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:35.546-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:20.026-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="php-gd is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:98735"/>
          <criterion comment="php-soap is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:99051"/>
          <criterion comment="php-common is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:98453"/>
          <criterion comment="php-odbc is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:98743"/>
          <criterion comment="php-mysql is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:98633"/>
          <criterion comment="php is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:99087"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:98862"/>
          <criterion comment="php-cli is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:98393"/>
          <criterion comment="php-mbstring is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:98907"/>
          <criterion comment="php-pgsql is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:98984"/>
          <criterion comment="php-xml is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:98448"/>
          <criterion comment="php-dba is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:98982"/>
          <criterion comment="php-devel is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:99162"/>
          <criterion comment="php-bcmath is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:98557"/>
          <criterion comment="php-imap is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:99063"/>
          <criterion comment="php-ncurses is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:98711"/>
          <criterion comment="php-snmp is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:98220"/>
          <criterion comment="php-pdo is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:98694"/>
          <criterion comment="php-ldap is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:98913"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21388" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0699: openssl security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0699-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0699.html"/>
        <reference source="CESA" ref_id="CESA-2012:0699"/>
        <reference source="CVE" ref_id="CVE-2012-2333" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2333.html"/>
        <description>Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:42.503-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:35.120-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:19.498-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:93493"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:93567"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:93399"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:93414"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:92594"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:92832"/>
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:93576"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21382" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0449: rhn-client-tools security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>rhn-client-tools</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0449-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0449.html"/>
        <reference source="CVE" ref_id="CVE-2010-1439" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1439.html"/>
        <description>yum-rhn-plugin in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Enterprise Linux (RHEL) 5 and Fedora uses world-readable permissions for the /var/spool/up2date/loginAuth.pkl file, which allows local users to access the Red Hat Network profile, and possibly prevent future security updates, by leveraging authentication data from this file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:33.895-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:34.777-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:19.027-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="rhn-check is earlier than 0:0.4.20-33.el5_5.2" test_ref="oval:org.mitre.oval:tst:98945"/>
          <criterion comment="rhn-setup-gnome is earlier than 0:0.4.20-33.el5_5.2" test_ref="oval:org.mitre.oval:tst:99013"/>
          <criterion comment="rhn-client-tools is earlier than 0:0.4.20-33.el5_5.2" test_ref="oval:org.mitre.oval:tst:99042"/>
          <criterion comment="rhn-setup is earlier than 0:0.4.20-33.el5_5.2" test_ref="oval:org.mitre.oval:tst:99405"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21381" version="107" class="patch">
      <metadata>
        <title>RHSA-2011:0182: openoffice.org security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openoffice.org</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0182-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0182.html"/>
        <reference source="CESA" ref_id="CESA-2011:0182"/>
        <reference source="CVE" ref_id="CVE-2010-3450" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3450.html"/>
        <reference source="CVE" ref_id="CVE-2010-3451" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3451.html"/>
        <reference source="CVE" ref_id="CVE-2010-3452" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3452.html"/>
        <reference source="CVE" ref_id="CVE-2010-3453" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3453.html"/>
        <reference source="CVE" ref_id="CVE-2010-3454" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3454.html"/>
        <reference source="CVE" ref_id="CVE-2010-3689" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3689.html"/>
        <reference source="CVE" ref_id="CVE-2010-4253" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4253.html"/>
        <reference source="CVE" ref_id="CVE-2010-4643" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4643.html"/>
        <description>Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:13.386-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:34.414-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:18.591-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openoffice.org is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96477"/>
          <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96751"/>
          <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97061"/>
          <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97134"/>
          <criterion comment="openoffice.org-ure is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97041"/>
          <criterion comment="openoffice.org-langpack-nl is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97170"/>
          <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96305"/>
          <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97220"/>
          <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97083"/>
          <criterion comment="openoffice.org-calc is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96507"/>
          <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96343"/>
          <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96666"/>
          <criterion comment="openoffice.org-testtools is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96770"/>
          <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96761"/>
          <criterion comment="openoffice.org-headless is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97138"/>
          <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97114"/>
          <criterion comment="openoffice.org-langpack-it is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97092"/>
          <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96734"/>
          <criterion comment="openoffice.org-base is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96272"/>
          <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97210"/>
          <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96791"/>
          <criterion comment="openoffice.org-langpack-es is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97127"/>
          <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97026"/>
          <criterion comment="openoffice.org-draw is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97063"/>
          <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96998"/>
          <criterion comment="openoffice.org-langpack-ar is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97099"/>
          <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96898"/>
          <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97157"/>
          <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97200"/>
          <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97166"/>
          <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96999"/>
          <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97087"/>
          <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96895"/>
          <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97180"/>
          <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96438"/>
          <criterion comment="openoffice.org-langpack-ru is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97198"/>
          <criterion comment="openoffice.org-xsltfilter is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97169"/>
          <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97238"/>
          <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97060"/>
          <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97155"/>
          <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97105"/>
          <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96806"/>
          <criterion comment="openoffice.org-langpack-bn is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97097"/>
          <criterion comment="openoffice.org-graphicfilter is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96547"/>
          <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97215"/>
          <criterion comment="openoffice.org-pyuno is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97219"/>
          <criterion comment="openoffice.org-writer is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96377"/>
          <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97164"/>
          <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97209"/>
          <criterion comment="openoffice.org-sdk is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97122"/>
          <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96487"/>
          <criterion comment="openoffice.org-langpack-fr is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96296"/>
          <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97141"/>
          <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97147"/>
          <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96963"/>
          <criterion comment="openoffice.org-math is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96891"/>
          <criterion comment="openoffice.org-langpack-ur is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96944"/>
          <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96738"/>
          <criterion comment="openoffice.org-core is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97111"/>
          <criterion comment="openoffice.org-impress is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97112"/>
          <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96610"/>
          <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96989"/>
          <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96723"/>
          <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96665"/>
          <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96969"/>
          <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96661"/>
          <criterion comment="openoffice.org-sdk-doc is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96747"/>
          <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96899"/>
          <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97075"/>
          <criterion comment="openoffice.org-emailmerge is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97010"/>
          <criterion comment="openoffice.org-javafilter is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97224"/>
          <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:96632"/>
          <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97098"/>
          <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97006"/>
          <criterion comment="openoffice.org-langpack-sv is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97162"/>
          <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97017"/>
          <criterion comment="openoffice.org-langpack-de is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97066"/>
          <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:97212"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21377" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1036: postgresql security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1036-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1036.html"/>
        <reference source="CESA" ref_id="CESA-2012:1036"/>
        <reference source="CVE" ref_id="CVE-2012-2143" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2143.html"/>
        <description>The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:38.313-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:34.278-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:18.360-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="postgresql-test is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:93955"/>
          <criterion comment="postgresql-pl is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:93901"/>
          <criterion comment="postgresql is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:93864"/>
          <criterion comment="postgresql-libs is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:93078"/>
          <criterion comment="postgresql-contrib is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:94015"/>
          <criterion comment="postgresql-tcl is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:93987"/>
          <criterion comment="postgresql-python is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:94016"/>
          <criterion comment="postgresql-devel is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:94047"/>
          <criterion comment="postgresql-server is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:93767"/>
          <criterion comment="postgresql-docs is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:93571"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21376" version="83" class="patch">
      <metadata>
        <title>RHSA-2012:0722: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0722-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0722.html"/>
        <reference source="CVE" ref_id="CVE-2012-2034" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2034.html"/>
        <reference source="CVE" ref_id="CVE-2012-2035" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2035.html"/>
        <reference source="CVE" ref_id="CVE-2012-2036" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2036.html"/>
        <reference source="CVE" ref_id="CVE-2012-2037" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2037.html"/>
        <reference source="CVE" ref_id="CVE-2012-2038" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2038.html"/>
        <reference source="CVE" ref_id="CVE-2012-2039" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2039.html"/>
        <description>Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:21.389-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:34.120-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:18.125-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21376 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:06.126-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:00.130-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.20-1.el5" test_ref="oval:org.mitre.oval:tst:137696"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.20-1.el6" test_ref="oval:org.mitre.oval:tst:93641"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21374" version="81" class="patch">
      <metadata>
        <title>RHSA-2010:0037: acroread security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0037-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0037.html"/>
        <reference source="CVE" ref_id="CVE-2009-3953" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3953.html"/>
        <reference source="CVE" ref_id="CVE-2009-3954" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3954.html"/>
        <reference source="CVE" ref_id="CVE-2009-3955" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3955.html"/>
        <reference source="CVE" ref_id="CVE-2009-3956" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3956.html"/>
        <reference source="CVE" ref_id="CVE-2009-3959" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3959.html"/>
        <reference source="CVE" ref_id="CVE-2009-4324" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4324.html"/>
        <description>Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:34.305-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:33.894-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:17.680-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="acroread-plugin is earlier than 0:9.3-1.el5" test_ref="oval:org.mitre.oval:tst:98967"/>
          <criterion comment="acroread is earlier than 0:9.3-1.el5" test_ref="oval:org.mitre.oval:tst:98397"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21373" version="55" class="patch">
      <metadata>
        <title>RHSA-2012:1590: libtiff security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1590-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1590.html"/>
        <reference source="CESA" ref_id="CESA-2012:1590"/>
        <reference source="CVE" ref_id="CVE-2012-3401" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3401.html"/>
        <reference source="CVE" ref_id="CVE-2012-4447" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4447.html"/>
        <reference source="CVE" ref_id="CVE-2012-4564" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4564.html"/>
        <reference source="CVE" ref_id="CVE-2012-5581" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5581.html"/>
        <description>Stack-based buffer overflow in tif_dir.c in LibTIFF before 4.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DOTRANGE tag in a TIFF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:26.906-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:33.752-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:17.502-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libtiff is earlier than 0:3.8.2-18.el5_8" test_ref="oval:org.mitre.oval:tst:94475"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-18.el5_8" test_ref="oval:org.mitre.oval:tst:94221"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libtiff is earlier than 0:3.9.4-9.el6_3" test_ref="oval:org.mitre.oval:tst:94950"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-9.el6_3" test_ref="oval:org.mitre.oval:tst:94836"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-9.el6_3" test_ref="oval:org.mitre.oval:tst:94861"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21371" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:1222: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1222-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1222.html"/>
        <reference source="CESA" ref_id="CESA-2012:1222"/>
        <reference source="CVE" ref_id="CVE-2012-0547" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0547.html"/>
        <reference source="CVE" ref_id="CVE-2012-1682" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1682.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-3136.  NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "XMLDecoder security issue via ClassFinder."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:08.301-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:33.574-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:17.260-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.28.1.10.9.el5_8" test_ref="oval:org.mitre.oval:tst:94349"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.28.1.10.9.el5_8" test_ref="oval:org.mitre.oval:tst:94364"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.28.1.10.9.el5_8" test_ref="oval:org.mitre.oval:tst:94411"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.28.1.10.9.el5_8" test_ref="oval:org.mitre.oval:tst:94427"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.28.1.10.9.el5_8" test_ref="oval:org.mitre.oval:tst:94489"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21370" version="68" class="patch">
      <metadata>
        <title>RHSA-2012:0107: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0107-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0107.html"/>
        <reference source="CESA" ref_id="CESA-2012:0107"/>
        <reference source="CVE" ref_id="CVE-2011-3638" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3638.html"/>
        <reference source="CVE" ref_id="CVE-2011-4086" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4086.html"/>
        <reference source="CVE" ref_id="CVE-2011-4127" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4127.html"/>
        <reference source="CVE" ref_id="CVE-2012-0028" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0028.html"/>
        <reference source="CVE" ref_id="CVE-2012-0207" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0207.html"/>
        <description>The igmp_heard_query function in net/ipv4/igmp.c in the Linux kernel before 3.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and panic) via IGMP packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:21.595-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:33.425-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:17.053-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:92963"/>
          <criterion comment="kernel is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:92218"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:92521"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:92984"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:92857"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:92859"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:93018"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:92560"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:92922"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:92499"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:92878"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:92944"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21366" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0518: openssl security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssl</product>
          <product>openssl097a</product>
          <product>openssl098e</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0518-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0518.html"/>
        <reference source="CESA" ref_id="CESA-2012:0518"/>
        <reference source="CVE" ref_id="CVE-2012-2110" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2110.html"/>
        <description>The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:55.683-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:33.157-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:16.651-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:92802"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:93327"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:93345"/>
            <criterion comment="openssl097a is earlier than 0:0.9.7a-11.el5_8.2" test_ref="oval:org.mitre.oval:tst:93396"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 and Centos 6 section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:93126"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:92825"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:93186"/>
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:93154"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criterion comment="openssl098e is earlier than 0:0.9.8e-17.el6.centos.2" test_ref="oval:org.mitre.oval:tst:94870"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="openssl098e is earlier than 0:0.9.8e-17.el6_2.2" test_ref="oval:org.mitre.oval:tst:93183"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21365" version="68" class="patch">
      <metadata>
        <title>RHSA-2012:0126: glibc security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0126-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0126.html"/>
        <reference source="CESA" ref_id="CESA-2012:0126"/>
        <reference source="CVE" ref_id="CVE-2009-5029" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-5029.html"/>
        <reference source="CVE" ref_id="CVE-2009-5064" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-5064.html"/>
        <reference source="CVE" ref_id="CVE-2010-0830" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0830.html"/>
        <reference source="CVE" ref_id="CVE-2011-1089" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1089.html"/>
        <reference source="CVE" ref_id="CVE-2011-4609" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4609.html"/>
        <description>The svc_run function in the RPC implementation in glibc before 2.15 allows remote attackers to cause a denial of service (CPU consumption) via a large number of RPC connections.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:40.876-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:33.008-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:16.380-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="nscd is earlier than 0:2.5-65.el5_7.3" test_ref="oval:org.mitre.oval:tst:92619"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-65.el5_7.3" test_ref="oval:org.mitre.oval:tst:92478"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-65.el5_7.3" test_ref="oval:org.mitre.oval:tst:93044"/>
          <criterion comment="glibc-common is earlier than 0:2.5-65.el5_7.3" test_ref="oval:org.mitre.oval:tst:93041"/>
          <criterion comment="glibc is earlier than 0:2.5-65.el5_7.3" test_ref="oval:org.mitre.oval:tst:92939"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-65.el5_7.3" test_ref="oval:org.mitre.oval:tst:92772"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21364" version="107" class="patch">
      <metadata>
        <title>RHSA-2012:0006: java-1.4.2-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.4.2-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0006-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0006.html"/>
        <reference source="CVE" ref_id="CVE-2011-3389" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3389.html"/>
        <reference source="CVE" ref_id="CVE-2011-3545" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3545.html"/>
        <reference source="CVE" ref_id="CVE-2011-3547" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3547.html"/>
        <reference source="CVE" ref_id="CVE-2011-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3548.html"/>
        <reference source="CVE" ref_id="CVE-2011-3549" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3549.html"/>
        <reference source="CVE" ref_id="CVE-2011-3552" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3552.html"/>
        <reference source="CVE" ref_id="CVE-2011-3556" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3556.html"/>
        <reference source="CVE" ref_id="CVE-2011-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3557.html"/>
        <reference source="CVE" ref_id="CVE-2011-3560" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3560.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and integrity, related to JSSE.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:16.795-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:31.757-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:16.041-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.11-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:92511"/>
          <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.11-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:92351"/>
          <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.11-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:92672"/>
          <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.11-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:92797"/>
          <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.11-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:92554"/>
          <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.11-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:92501"/>
          <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.11-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:92711"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21363" version="55" class="patch">
      <metadata>
        <title>RHSA-2012:0060: openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0060-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0060.html"/>
        <reference source="CESA" ref_id="CESA-2012:0060"/>
        <reference source="CVE" ref_id="CVE-2011-4108" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4108.html"/>
        <reference source="CVE" ref_id="CVE-2011-4109" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4109.html"/>
        <reference source="CVE" ref_id="CVE-2011-4576" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4576.html"/>
        <reference source="CVE" ref_id="CVE-2011-4619" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4619.html"/>
        <description>The Server Gated Cryptography (SGC) implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly handle handshake restarts, which allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:30.584-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:31.629-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:15.868-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl is earlier than 0:0.9.8e-20.el5_7.1" test_ref="oval:org.mitre.oval:tst:92349"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-20.el5_7.1" test_ref="oval:org.mitre.oval:tst:92576"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-20.el5_7.1" test_ref="oval:org.mitre.oval:tst:92610"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl is earlier than 0:0.9.8e-20.el5_7.1.0.1.centos" test_ref="oval:org.mitre.oval:tst:94650"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-20.el5_7.1.0.1.centos" test_ref="oval:org.mitre.oval:tst:94788"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-20.el5_7.1.0.1.centos" test_ref="oval:org.mitre.oval:tst:94859"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21359" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1140: dhcp security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>dhcp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1140-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1140.html"/>
        <reference source="CESA" ref_id="CESA-2012:1140"/>
        <reference source="CVE" ref_id="CVE-2012-3571" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3571.html"/>
        <description>ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:54.263-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:31.555-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:15.758-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libdhcp4client-devel is earlier than 12:3.0.5-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:94375"/>
          <criterion comment="dhclient is earlier than 12:3.0.5-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:94288"/>
          <criterion comment="dhcp is earlier than 12:3.0.5-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:94321"/>
          <criterion comment="libdhcp4client is earlier than 12:3.0.5-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:94283"/>
          <criterion comment="dhcp-devel is earlier than 12:3.0.5-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:93995"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21356" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:1263: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1263-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1263.html"/>
        <reference source="CESA" ref_id="CESA-2012:1263"/>
        <reference source="CVE" ref_id="CVE-2012-3488" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3488.html"/>
        <reference source="CVE" ref_id="CVE-2012-3489" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3489.html"/>
        <description>The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:21.958-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:31.369-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:15.566-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94123"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94376"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94506"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94217"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94038"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94537"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:93867"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94530"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94296"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94264"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94344"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94212"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:94457"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:94531"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:93983"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:94490"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:94445"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:94185"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:93982"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:94410"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:94332"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:93946"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21353" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0397: glibc security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0397-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0397.html"/>
        <reference source="CESA" ref_id="CESA-2012:0397"/>
        <reference source="CVE" ref_id="CVE-2012-0864" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0864.html"/>
        <description>Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dependent attackers to bypass the FORTIFY_SOURCE protection mechanism, conduct format string attacks, and write to arbitrary memory via a large number of arguments.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:25.302-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:31.152-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:15.342-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="nscd is earlier than 0:2.5-81.el5_8.1" test_ref="oval:org.mitre.oval:tst:93004"/>
          <criterion comment="glibc is earlier than 0:2.5-81.el5_8.1" test_ref="oval:org.mitre.oval:tst:92967"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-81.el5_8.1" test_ref="oval:org.mitre.oval:tst:92906"/>
          <criterion comment="glibc-common is earlier than 0:2.5-81.el5_8.1" test_ref="oval:org.mitre.oval:tst:93116"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-81.el5_8.1" test_ref="oval:org.mitre.oval:tst:92769"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-81.el5_8.1" test_ref="oval:org.mitre.oval:tst:93103"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21349" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0317: libpng security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libpng</product>
          <product>libpng10</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0317-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0317.html"/>
        <reference source="CESA" ref_id="CESA-2012:0317"/>
        <reference source="CVE" ref_id="CVE-2011-3026" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3026.html"/>
        <description>Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:42.171-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:19.176-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:15.239-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpng-static is earlier than 2:1.2.46-2.el6_2" test_ref="oval:org.mitre.oval:tst:93076"/>
            <criterion comment="libpng-devel is earlier than 2:1.2.46-2.el6_2" test_ref="oval:org.mitre.oval:tst:93067"/>
            <criterion comment="libpng is earlier than 2:1.2.46-2.el6_2" test_ref="oval:org.mitre.oval:tst:92956"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpng-devel is earlier than 2:1.2.10-15.el5_7" test_ref="oval:org.mitre.oval:tst:92474"/>
            <criterion comment="libpng is earlier than 2:1.2.10-15.el5_7" test_ref="oval:org.mitre.oval:tst:92710"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21348" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1136: openoffice.org security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>openoffice.org</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1136-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1136.html"/>
        <reference source="CESA" ref_id="CESA-2012:1136"/>
        <reference source="CVE" ref_id="CVE-2012-2665" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2665.html"/>
        <description>Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:48.830-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:18.892-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:14.968-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94300"/>
          <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94046"/>
          <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94378"/>
          <criterion comment="openoffice.org-xsltfilter is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94218"/>
          <criterion comment="openoffice.org-langpack-ur is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94194"/>
          <criterion comment="openoffice.org-core is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:93648"/>
          <criterion comment="openoffice.org-calc is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94358"/>
          <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94145"/>
          <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94374"/>
          <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94369"/>
          <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94341"/>
          <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94442"/>
          <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94363"/>
          <criterion comment="openoffice.org-langpack-fr is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:93601"/>
          <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:93432"/>
          <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:93918"/>
          <criterion comment="openoffice.org-ure is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94325"/>
          <criterion comment="openoffice.org-sdk-doc is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94193"/>
          <criterion comment="openoffice.org-sdk is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94143"/>
          <criterion comment="openoffice.org-langpack-ar is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94090"/>
          <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94113"/>
          <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94339"/>
          <criterion comment="openoffice.org-testtools is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94365"/>
          <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94267"/>
          <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94205"/>
          <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94370"/>
          <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94224"/>
          <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94043"/>
          <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94346"/>
          <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:93948"/>
          <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:93783"/>
          <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94074"/>
          <criterion comment="openoffice.org-writer is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94311"/>
          <criterion comment="openoffice.org-pyuno is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94219"/>
          <criterion comment="openoffice.org-math is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:93675"/>
          <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:93940"/>
          <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94155"/>
          <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94039"/>
          <criterion comment="openoffice.org-emailmerge is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94310"/>
          <criterion comment="openoffice.org-javafilter is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94228"/>
          <criterion comment="openoffice.org-langpack-sv is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94204"/>
          <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94328"/>
          <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94343"/>
          <criterion comment="openoffice.org is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:93777"/>
          <criterion comment="openoffice.org-langpack-it is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:93859"/>
          <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94073"/>
          <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94351"/>
          <criterion comment="openoffice.org-base is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94102"/>
          <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:93906"/>
          <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94213"/>
          <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94085"/>
          <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94380"/>
          <criterion comment="openoffice.org-langpack-ru is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94326"/>
          <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94266"/>
          <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94247"/>
          <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94366"/>
          <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94304"/>
          <criterion comment="openoffice.org-langpack-bn is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94314"/>
          <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94105"/>
          <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94333"/>
          <criterion comment="openoffice.org-langpack-es is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:93647"/>
          <criterion comment="openoffice.org-langpack-nl is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94423"/>
          <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94222"/>
          <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94268"/>
          <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:93447"/>
          <criterion comment="openoffice.org-impress is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:93821"/>
          <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94278"/>
          <criterion comment="openoffice.org-langpack-de is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94281"/>
          <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94242"/>
          <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94200"/>
          <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94004"/>
          <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94397"/>
          <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:93922"/>
          <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94188"/>
          <criterion comment="openoffice.org-draw is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94406"/>
          <criterion comment="openoffice.org-headless is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:93781"/>
          <criterion comment="openoffice.org-graphicfilter is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:93560"/>
          <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:94368"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21347" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0721: kernel security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0721-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0721.html"/>
        <reference source="CESA" ref_id="CESA-2012:0721"/>
        <reference source="CVE" ref_id="CVE-2012-0217" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0217.html"/>
        <reference source="CVE" ref_id="CVE-2012-2934" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2934.html"/>
        <description>Xen 4.0, and 4.1, when running a 64-bit PV guest on "older" AMD CPUs, does not properly protect against a certain AMD processor bug, which allows local guest OS users to cause a denial of service (host hang) via sequential execution of instructions across a non-canonical boundary, a different vulnerability than CVE-2012-0217.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:12.927-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:18.717-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:14.624-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:93533"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:93097"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:93879"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:93862"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:93739"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:93796"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:93749"/>
          <criterion comment="kernel is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:93871"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:93551"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:93873"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:93438"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:93639"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21346" version="94" class="patch">
      <metadata>
        <title>RHSA-2012:0033: php security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0033-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0033.html"/>
        <reference source="CESA" ref_id="CESA-2012:0033"/>
        <reference source="CVE" ref_id="CVE-2011-0708" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0708.html"/>
        <reference source="CVE" ref_id="CVE-2011-1148" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1148.html"/>
        <reference source="CVE" ref_id="CVE-2011-1466" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1466.html"/>
        <reference source="CVE" ref_id="CVE-2011-1469" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1469.html"/>
        <reference source="CVE" ref_id="CVE-2011-2202" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2202.html"/>
        <reference source="CVE" ref_id="CVE-2011-4566" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4566.html"/>
        <reference source="CVE" ref_id="CVE-2011-4885" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4885.html"/>
        <description>PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:03.937-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:18.506-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:14.292-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="php-soap is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:92787"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:92598"/>
          <criterion comment="php-common is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:92226"/>
          <criterion comment="php-odbc is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:92163"/>
          <criterion comment="php is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:92105"/>
          <criterion comment="php-cli is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:92575"/>
          <criterion comment="php-mysql is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:92618"/>
          <criterion comment="php-mbstring is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:92605"/>
          <criterion comment="php-pgsql is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:92696"/>
          <criterion comment="php-ncurses is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:92319"/>
          <criterion comment="php-xml is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:92563"/>
          <criterion comment="php-dba is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:92446"/>
          <criterion comment="php-snmp is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:92562"/>
          <criterion comment="php-bcmath is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:92706"/>
          <criterion comment="php-gd is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:91848"/>
          <criterion comment="php-devel is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:92496"/>
          <criterion comment="php-ldap is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:92540"/>
          <criterion comment="php-imap is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:92553"/>
          <criterion comment="php-pdo is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:92073"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21345" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0465: samba security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0465-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0465.html"/>
        <reference source="CESA" ref_id="CESA-2012:0465"/>
        <reference source="CVE" ref_id="CVE-2012-1182" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1182.html"/>
        <description>The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:01.730-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:18.398-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:14.138-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba-client is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:93248"/>
            <criterion comment="samba is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:92770"/>
            <criterion comment="samba-common is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:93185"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:93128"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:93259"/>
            <criterion comment="libsmbclient is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:93323"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba-client is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93137"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93336"/>
            <criterion comment="samba is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93134"/>
            <criterion comment="samba-winbind is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93255"/>
            <criterion comment="samba-common is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93167"/>
            <criterion comment="samba-doc is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93346"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:92981"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93112"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93262"/>
            <criterion comment="libsmbclient is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93311"/>
            <criterion comment="samba-swat is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93148"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:92630"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21343" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0150: Red Hat Enterprise Linux 5.8 kernel update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0150-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0150.html"/>
        <reference source="CVE" ref_id="CVE-2011-1083" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1083.html"/>
        <description>The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to cause a denial of service (CPU consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:36.031-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:18.064-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:13.628-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:93028"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:92068"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:92694"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:92729"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:92931"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:92645"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:92925"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:93037"/>
          <criterion comment="kernel is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:92866"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:92863"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:92935"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:92773"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21341" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1361: xulrunner security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1361-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1361.html"/>
        <reference source="CESA" ref_id="CESA-2012:1361"/>
        <reference source="CVE" ref_id="CVE-2012-4193" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4193.html"/>
        <description>Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and read the properties of a Location object, or execute arbitrary JavaScript code, via a crafted web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:17.563-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:17.941-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:13.493-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-2.el5_8" test_ref="oval:org.mitre.oval:tst:94320"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-2.el5_8" test_ref="oval:org.mitre.oval:tst:94600"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-2.el6_3" test_ref="oval:org.mitre.oval:tst:94757"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-2.el6_3" test_ref="oval:org.mitre.oval:tst:94756"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-2.el6.centos" test_ref="oval:org.mitre.oval:tst:94746"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-2.el6.centos" test_ref="oval:org.mitre.oval:tst:95038"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21339" version="42" class="patch">
      <metadata>
        <title>RHSA-2012:0678: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0678-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0678.html"/>
        <reference source="CESA" ref_id="CESA-2012:0678"/>
        <reference source="CVE" ref_id="CVE-2012-0866" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0866.html"/>
        <reference source="CVE" ref_id="CVE-2012-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0867.html"/>
        <reference source="CVE" ref_id="CVE-2012-0868" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0868.html"/>
        <description>CRLF injection vulnerability in pg_dump in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows user-assisted remote attackers to execute arbitrary SQL commands via a crafted file containing object names with newlines, which are inserted into an SQL script that is used when the database is restored.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:47.575-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:17.457-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:13.023-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93559"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93002"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93322"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93206"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93528"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93478"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93564"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93331"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93300"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:92586"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93333"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93279"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93417"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93230"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93475"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93387"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93469"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93353"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93549"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93419"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93268"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93310"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21336" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0019: php53 and php security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0019-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0019.html"/>
        <reference source="CESA" ref_id="CESA-2012:0019"/>
        <reference source="CVE" ref_id="CVE-2011-4566" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4566.html"/>
        <reference source="CVE" ref_id="CVE-2011-4885" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4885.html"/>
        <description>PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:45.594-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:17.070-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:12.594-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92318"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92528"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92709"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92724"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92585"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92698"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92692"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92723"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92728"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92722"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92531"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92693"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92746"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92757"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92638"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92396"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92257"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92601"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92280"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92631"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92790"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92359"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92120"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92442"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92417"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92520"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92759"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92025"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92677"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92707"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92153"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92372"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92382"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92756"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92607"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92604"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92681"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92401"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92673"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92628"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92469"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92432"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92290"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92656"/>
            <criterion comment="php53 is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92697"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92348"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92735"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21334" version="83" class="patch">
      <metadata>
        <title>RHSA-2012:1245: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1245-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1245.html"/>
        <reference source="CVE" ref_id="CVE-2012-1713" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1713.html"/>
        <reference source="CVE" ref_id="CVE-2012-1716" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1716.html"/>
        <reference source="CVE" ref_id="CVE-2012-1717" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1717.html"/>
        <reference source="CVE" ref_id="CVE-2012-1718" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1718.html"/>
        <reference source="CVE" ref_id="CVE-2012-1719" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1719.html"/>
        <reference source="CVE" ref_id="CVE-2012-1725" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1725.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, and 5 update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:11.634-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:16.803-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:12.286-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21334 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:27.021-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:59.248-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.14.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137922"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.14.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137620"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.14.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137738"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.14.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137917"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.14.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137002"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.14.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137929"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.14.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137504"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.14.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137450"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94282"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94362"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94293"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94256"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:93911"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94298"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94470"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21333" version="159" class="patch">
      <metadata>
        <title>RHSA-2012:0515: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0515-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0515.html"/>
        <reference source="CESA" ref_id="CESA-2012:0515"/>
        <reference source="CVE" ref_id="CVE-2011-3062" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3062.html"/>
        <reference source="CVE" ref_id="CVE-2012-0467" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0467.html"/>
        <reference source="CVE" ref_id="CVE-2012-0468" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0468.html"/>
        <reference source="CVE" ref_id="CVE-2012-0469" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0469.html"/>
        <reference source="CVE" ref_id="CVE-2012-0470" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0470.html"/>
        <reference source="CVE" ref_id="CVE-2012-0471" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0471.html"/>
        <reference source="CVE" ref_id="CVE-2012-0472" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0472.html"/>
        <reference source="CVE" ref_id="CVE-2012-0473" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0473.html"/>
        <reference source="CVE" ref_id="CVE-2012-0474" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0474.html"/>
        <reference source="CVE" ref_id="CVE-2012-0477" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0477.html"/>
        <reference source="CVE" ref_id="CVE-2012-0478" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0478.html"/>
        <reference source="CVE" ref_id="CVE-2012-0479" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0479.html"/>
        <description>Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to spoof the address bar via an https URL for invalid (1) RSS or (2) Atom XML content.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:17.498-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:16.413-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:11.878-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:93130"/>
            <criterion comment="xulrunner is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:92785"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:10.0.4-1.el5.centos" test_ref="oval:org.mitre.oval:tst:95029"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:93351"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:93270"/>
            <criterion comment="xulrunner is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:92884"/>
            <criterion comment="firefox is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:92737"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.4-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94935"/>
            <criterion comment="xulrunner is earlier than 0:10.0.4-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94820"/>
            <criterion comment="firefox is earlier than 0:10.0.4-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94789"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21332" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0070: ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0070-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0070.html"/>
        <reference source="CESA" ref_id="CESA-2012:0070"/>
        <reference source="CVE" ref_id="CVE-2011-3009" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3009.html"/>
        <reference source="CVE" ref_id="CVE-2011-4815" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4815.html"/>
        <description>Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:43.859-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:16.264-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:11.724-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="ruby-ri is earlier than 0:1.8.5-22.el5_7.1" test_ref="oval:org.mitre.oval:tst:92748"/>
          <criterion comment="ruby-mode is earlier than 0:1.8.5-22.el5_7.1" test_ref="oval:org.mitre.oval:tst:92421"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.5-22.el5_7.1" test_ref="oval:org.mitre.oval:tst:92775"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.5-22.el5_7.1" test_ref="oval:org.mitre.oval:tst:92445"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.5-22.el5_7.1" test_ref="oval:org.mitre.oval:tst:92476"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.5-22.el5_7.1" test_ref="oval:org.mitre.oval:tst:92667"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.5-22.el5_7.1" test_ref="oval:org.mitre.oval:tst:92688"/>
          <criterion comment="ruby is earlier than 0:1.8.5-22.el5_7.1" test_ref="oval:org.mitre.oval:tst:92716"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.5-22.el5_7.1" test_ref="oval:org.mitre.oval:tst:92856"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21326" version="107" class="patch">
      <metadata>
        <title>RHSA-2012:1258: quagga security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>quagga</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1258-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1258.html"/>
        <reference source="CESA" ref_id="CESA-2012:1258"/>
        <reference source="CVE" ref_id="CVE-2010-1674" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1674.html"/>
        <reference source="CVE" ref_id="CVE-2011-3323" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3323.html"/>
        <reference source="CVE" ref_id="CVE-2011-3324" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3324.html"/>
        <reference source="CVE" ref_id="CVE-2011-3325" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3325.html"/>
        <reference source="CVE" ref_id="CVE-2011-3326" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3326.html"/>
        <reference source="CVE" ref_id="CVE-2011-3327" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3327.html"/>
        <reference source="CVE" ref_id="CVE-2012-0249" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0249.html"/>
        <reference source="CVE" ref_id="CVE-2012-0250" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0250.html"/>
        <description>Buffer overflow in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (daemon crash) via a Link State Update (aka LS Update) packet containing a network-LSA link-state advertisement for which the data-structure length is smaller than the value in the Length header field.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:03.391-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:15.421-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:11.133-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="quagga-devel is earlier than 0:0.98.6-7.el5_8.1" test_ref="oval:org.mitre.oval:tst:94305"/>
          <criterion comment="quagga is earlier than 0:0.98.6-7.el5_8.1" test_ref="oval:org.mitre.oval:tst:94084"/>
          <criterion comment="quagga-contrib is earlier than 0:0.98.6-7.el5_8.1" test_ref="oval:org.mitre.oval:tst:93655"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21325" version="107" class="patch">
      <metadata>
        <title>RHSA-2012:1201: tetex security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>tetex</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1201-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1201.html"/>
        <reference source="CESA" ref_id="CESA-2012:1201"/>
        <reference source="CVE" ref_id="CVE-2010-2642" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2642.html"/>
        <reference source="CVE" ref_id="CVE-2010-3702" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3702.html"/>
        <reference source="CVE" ref_id="CVE-2010-3704" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3704.html"/>
        <reference source="CVE" ref_id="CVE-2011-0433" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0433.html"/>
        <reference source="CVE" ref_id="CVE-2011-0764" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0764.html"/>
        <reference source="CVE" ref_id="CVE-2011-1552" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1552.html"/>
        <reference source="CVE" ref_id="CVE-2011-1553" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1553.html"/>
        <reference source="CVE" ref_id="CVE-2011-1554" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1554.html"/>
        <description>Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:06.901-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:15.149-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:10.936-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tetex-latex is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:94398"/>
          <criterion comment="tetex-doc is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:94172"/>
          <criterion comment="tetex is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:94251"/>
          <criterion comment="tetex-xdvi is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:94392"/>
          <criterion comment="tetex-afm is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:94422"/>
          <criterion comment="tetex-dvips is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:94383"/>
          <criterion comment="tetex-fonts is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:93465"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21322" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0705: openoffice.org security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>openoffice.org</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0705-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0705.html"/>
        <reference source="CESA" ref_id="CESA-2012:0705"/>
        <reference source="CVE" ref_id="CVE-2012-1149" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1149.html"/>
        <reference source="CVE" ref_id="CVE-2012-2334" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2334.html"/>
        <description>Integer overflow in filter/source/msfilter/msdffimp.cxx in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the length of an Escher graphics record in a PowerPoint (.ppt) document, which triggers a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:27.251-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:53.684-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:10.221-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93638"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93388"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93497"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93485"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93599"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93378"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92606"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93291"/>
            <criterion comment="openoffice.org-draw is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93552"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93544"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92627"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93163"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93448"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93054"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93488"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93171"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92820"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93153"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93545"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93504"/>
            <criterion comment="openoffice.org-calc is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92926"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93429"/>
            <criterion comment="openoffice.org-core is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93508"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93562"/>
            <criterion comment="openoffice.org-sdk is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92632"/>
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93216"/>
            <criterion comment="openoffice.org-pyuno is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93457"/>
            <criterion comment="openoffice.org is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93501"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93495"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93177"/>
            <criterion comment="openoffice.org-impress is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93271"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93476"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92821"/>
            <criterion comment="openoffice.org-sdk-doc is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93074"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93155"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93243"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93305"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93523"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93377"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93371"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93550"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93090"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93529"/>
            <criterion comment="openoffice.org-headless is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93449"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93313"/>
            <criterion comment="openoffice.org-testtools is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93106"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93129"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93466"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93489"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93553"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93479"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92806"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93360"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93430"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93568"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93532"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92927"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93468"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92611"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93463"/>
            <criterion comment="openoffice.org-javafilter is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92907"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93603"/>
            <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93509"/>
            <criterion comment="openoffice.org-base is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93563"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93569"/>
            <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92666"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93122"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93218"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93440"/>
            <criterion comment="openoffice.org-ure is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92993"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92870"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93610"/>
            <criterion comment="openoffice.org-math is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93588"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93401"/>
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93472"/>
            <criterion comment="openoffice.org-writer is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93409"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92704"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93169"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93734"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93659"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93635"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93662"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93424"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93723"/>
            <criterion comment="autocorr-af is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92810"/>
            <criterion comment="openoffice.org-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93670"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93204"/>
            <criterion comment="openoffice.org-langpack-dz is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93702"/>
            <criterion comment="openoffice.org-sdk-doc is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93768"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93697"/>
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93584"/>
            <criterion comment="broffice.org-brand is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93731"/>
            <criterion comment="autocorr-vi is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93464"/>
            <criterion comment="openoffice.org-langpack-uk is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93745"/>
            <criterion comment="autocorr-ja is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93598"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93703"/>
            <criterion comment="openoffice.org-testtools is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93653"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93735"/>
            <criterion comment="openoffice.org-calc is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93605"/>
            <criterion comment="openoffice.org-opensymbol-fonts is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93586"/>
            <criterion comment="autocorr-eu is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93361"/>
            <criterion comment="openoffice.org is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93543"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93730"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93737"/>
            <criterion comment="openoffice.org-presentation-minimizer is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93636"/>
            <criterion comment="autocorr-sl is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93556"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93684"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93754"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93631"/>
            <criterion comment="openoffice.org-draw is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93758"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93082"/>
            <criterion comment="openoffice.org-devel is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93580"/>
            <criterion comment="autocorr-ga is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93711"/>
            <criterion comment="openoffice.org-report-builder is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93683"/>
            <criterion comment="openoffice.org-calc-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93720"/>
            <criterion comment="autocorr-mn is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93676"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93587"/>
            <criterion comment="broffice.org-math is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93539"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93473"/>
            <criterion comment="autocorr-pl is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93392"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93575"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93227"/>
            <criterion comment="openoffice.org-base-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93557"/>
            <criterion comment="broffice.org-writer is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93203"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93715"/>
            <criterion comment="openoffice.org-brand is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93870"/>
            <criterion comment="broffice.org-impress is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93606"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93535"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93434"/>
            <criterion comment="autocorr-da is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92828"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93220"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93692"/>
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93264"/>
            <criterion comment="openoffice.org-langpack-pa is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93708"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93195"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93628"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93691"/>
            <criterion comment="openoffice.org-writer is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93652"/>
            <criterion comment="broffice.org-calc is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93301"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92881"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93614"/>
            <criterion comment="autocorr-tr is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93510"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93725"/>
            <criterion comment="autocorr-sv is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93182"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93490"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93719"/>
            <criterion comment="autocorr-fr is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93477"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93637"/>
            <criterion comment="autocorr-es is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92929"/>
            <criterion comment="openoffice.org-langpack-ro is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93682"/>
            <criterion comment="openoffice.org-langpack-en is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93272"/>
            <criterion comment="autocorr-fi is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92874"/>
            <criterion comment="openoffice.org-impress is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93590"/>
            <criterion comment="openoffice.org-javafilter is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93373"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93320"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93522"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93744"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93574"/>
            <criterion comment="openoffice.org-langpack-mai_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93498"/>
            <criterion comment="openoffice.org-wiki-publisher is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93281"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93690"/>
            <criterion comment="autocorr-de is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93622"/>
            <criterion comment="broffice.org-base is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93694"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93546"/>
            <criterion comment="openoffice.org-math is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93481"/>
            <criterion comment="autocorr-nl is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93395"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93433"/>
            <criterion comment="openoffice.org-draw-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93762"/>
            <criterion comment="openoffice.org-pyuno is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93572"/>
            <criterion comment="autocorr-bg is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93531"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93831"/>
            <criterion comment="openoffice.org-bsh is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93192"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93760"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93462"/>
            <criterion comment="openoffice.org-langpack-sr is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93484"/>
            <criterion comment="openoffice.org-math-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93807"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93435"/>
            <criterion comment="autocorr-ru is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93616"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93826"/>
            <criterion comment="autocorr-en is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93600"/>
            <criterion comment="autocorr-sk is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93511"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92924"/>
            <criterion comment="autocorr-lt is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93756"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93537"/>
            <criterion comment="autocorr-cs is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93693"/>
            <criterion comment="autocorr-pt is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93343"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93591"/>
            <criterion comment="openoffice.org-writer-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92771"/>
            <criterion comment="openoffice.org-sdk is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93582"/>
            <criterion comment="openoffice.org-rhino is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93087"/>
            <criterion comment="openoffice.org-presenter-screen is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93611"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93458"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93024"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93100"/>
            <criterion comment="openoffice.org-impress-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93592"/>
            <criterion comment="broffice.org-draw is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93470"/>
            <criterion comment="openoffice.org-pdfimport is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93482"/>
            <criterion comment="autocorr-fa is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93413"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92901"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93738"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93521"/>
            <criterion comment="autocorr-zh is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92831"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93649"/>
            <criterion comment="autocorr-ko is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93512"/>
            <criterion comment="openoffice.org-headless is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93542"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93673"/>
            <criterion comment="autocorr-it is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93515"/>
            <criterion comment="openoffice.org-ogltrans is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93761"/>
            <criterion comment="openoffice.org-base is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93642"/>
            <criterion comment="autocorr-hu is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93459"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93646"/>
            <criterion comment="openoffice.org-ure is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93374"/>
            <criterion comment="autocorr-lb is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93375"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92909"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21320" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0302: cups security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0302-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0302.html"/>
        <reference source="CVE" ref_id="CVE-2011-2896" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2896.html"/>
        <description>The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and earlier, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows remote attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2895.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:31.528-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:53.560-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:09.932-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="cups-lpd is earlier than 1:1.3.7-30.el5" test_ref="oval:org.mitre.oval:tst:92858"/>
          <criterion comment="cups-libs is earlier than 1:1.3.7-30.el5" test_ref="oval:org.mitre.oval:tst:92456"/>
          <criterion comment="cups-devel is earlier than 1:1.3.7-30.el5" test_ref="oval:org.mitre.oval:tst:92680"/>
          <criterion comment="cups is earlier than 1:1.3.7-30.el5" test_ref="oval:org.mitre.oval:tst:92833"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21318" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1116: perl-DBD-Pg security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>perl-DBD-Pg</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1116-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1116.html"/>
        <reference source="CESA" ref_id="CESA-2012:1116"/>
        <reference source="CVE" ref_id="CVE-2012-1151" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1151.html"/>
        <description>Multiple format string vulnerabilities in dbdimp.c in DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.19.0 for Perl allow remote PostgreSQL database servers to cause a denial of service (process crash) via format string specifiers in (1) a crafted database warning to the pg_warn function or (2) a crafted DBD statement to the dbd_st_prepare function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:34.595-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:53.484-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:09.811-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="perl-DBD-Pg is earlier than 0:1.49-4.el5_8" test_ref="oval:org.mitre.oval:tst:94094"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="perl-DBD-Pg is earlier than 0:2.15.1-4.el6_3" test_ref="oval:org.mitre.oval:tst:93969"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21314" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0093: php security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0093-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0093.html"/>
        <reference source="CESA" ref_id="CESA-2012:0093"/>
        <reference source="CVE" ref_id="CVE-2012-0830" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0830.html"/>
        <description>The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:34.346-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:52.959-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:08.896-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:93036"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92893"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92388"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92989"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92965"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92902"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92659"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92803"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92195"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92443"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92438"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92890"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92486"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92847"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92301"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92744"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92641"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:93042"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92923"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92596"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92934"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92932"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92910"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92583"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92671"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92867"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php-common is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92835"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92897"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:93017"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92732"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92886"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92690"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92422"/>
            <criterion comment="php is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92506"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92990"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92985"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92536"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92774"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92971"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92740"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92871"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92843"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92868"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92391"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92649"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21311" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0869: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0869-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0869.html"/>
        <reference source="CVE" ref_id="CVE-2011-2110" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2110.html"/>
        <description>Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in June 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:55.301-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:52.719-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:08.502-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.181.26-1.el5" test_ref="oval:org.mitre.oval:tst:98024"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.3.181.26-1.el6" test_ref="oval:org.mitre.oval:tst:98242"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21310" version="263" class="patch">
      <metadata>
        <title>RHSA-2012:1351: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1351-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1351.html"/>
        <reference source="CESA" ref_id="CESA-2012:1351"/>
        <reference source="CVE" ref_id="CVE-2012-1956" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1956.html"/>
        <reference source="CVE" ref_id="CVE-2012-3982" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3982.html"/>
        <reference source="CVE" ref_id="CVE-2012-3986" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3986.html"/>
        <reference source="CVE" ref_id="CVE-2012-3988" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3988.html"/>
        <reference source="CVE" ref_id="CVE-2012-3990" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3990.html"/>
        <reference source="CVE" ref_id="CVE-2012-3991" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3991.html"/>
        <reference source="CVE" ref_id="CVE-2012-3992" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3992.html"/>
        <reference source="CVE" ref_id="CVE-2012-3993" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3993.html"/>
        <reference source="CVE" ref_id="CVE-2012-3994" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3994.html"/>
        <reference source="CVE" ref_id="CVE-2012-3995" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3995.html"/>
        <reference source="CVE" ref_id="CVE-2012-4179" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4179.html"/>
        <reference source="CVE" ref_id="CVE-2012-4180" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4180.html"/>
        <reference source="CVE" ref_id="CVE-2012-4181" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4181.html"/>
        <reference source="CVE" ref_id="CVE-2012-4182" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4182.html"/>
        <reference source="CVE" ref_id="CVE-2012-4183" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4183.html"/>
        <reference source="CVE" ref_id="CVE-2012-4184" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4184.html"/>
        <reference source="CVE" ref_id="CVE-2012-4185" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4185.html"/>
        <reference source="CVE" ref_id="CVE-2012-4186" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4186.html"/>
        <reference source="CVE" ref_id="CVE-2012-4187" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4187.html"/>
        <reference source="CVE" ref_id="CVE-2012-4188" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4188.html"/>
        <description>Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:54.628-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:52.081-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:07.981-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-1.el5_8" test_ref="oval:org.mitre.oval:tst:94671"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94846"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.8-1.el6_3" test_ref="oval:org.mitre.oval:tst:94372"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.8-1.el6.centos" test_ref="oval:org.mitre.oval:tst:95080"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21308" version="7" class="patch">
      <metadata>
        <title>RHSA-2012:0153: sos security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>sos</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0153-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0153.html"/>
        <reference source="CESA" ref_id="CESA-2012:0153"/>
        <reference source="CVE" ref_id="CVE-2011-4083" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4083.html"/>
        <description>The sosreport utility in the Red Hat sos package before 1.7-9 and 2.x before 2.2-17 includes (1) Certificate-based Red Hat Network private entitlement keys and the (2) private key for the entitlement in an archive of debugging information, which might allow remote attackers to obtain sensitive information by reading the archive.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:52.784-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:51.590-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:07.563-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21308 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:43.069-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:36.655-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="sos is earlier than 0:1.7-9.62.el5" test_ref="oval:org.mitre.oval:tst:92796"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21307" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1363: bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1363-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1363.html"/>
        <reference source="CESA" ref_id="CESA-2012:1363"/>
        <reference source="CVE" ref_id="CVE-2012-5166" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5166.html"/>
        <description>ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:08.192-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:51.470-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:07.428-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bind is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:94747"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:94716"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:94743"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:94721"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:94030"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:94663"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:94424"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:94750"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bind is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:94460"/>
            <criterion comment="bind-chroot is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:94678"/>
            <criterion comment="bind-sdb is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:94569"/>
            <criterion comment="bind-libs is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:94202"/>
            <criterion comment="bind-devel is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:94555"/>
            <criterion comment="bind-utils is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:93984"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21301" version="44" class="patch">
      <metadata>
        <title>RHSA-2011:0862: subversion security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0862-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0862.html"/>
        <reference source="CVE" ref_id="CVE-2011-1752" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1752.html"/>
        <reference source="CVE" ref_id="CVE-2011-1783" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1783.html"/>
        <reference source="CVE" ref_id="CVE-2011-1921" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1921.html"/>
        <reference source="CESA-2011:0862" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-June/017614.html" ref_id="CESA-2011:0862-CentOS 5"/>
        <description>The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:14.691-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:51.150-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:07.124-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21301 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:29.244-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:58.767-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:137908"/>
            <criterion comment="subversion is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:137788"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:136956"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:137746"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:137709"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:137267"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:97942"/>
            <criterion comment="subversion is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:98168"/>
            <criterion comment="subversion-debuginfo is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:137907"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:97266"/>
            <criterion comment="subversion-gnome is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:97627"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:97915"/>
            <criterion comment="subversion-kde is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:97818"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:98187"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:98000"/>
            <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:98134"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21299" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1327: freeradius2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>freeradius2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1327-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1327.html"/>
        <reference source="CESA" ref_id="CESA-2012:1327"/>
        <reference source="CVE" ref_id="CVE-2012-3547" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3547.html"/>
        <description>Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 through 2.1.12, when using TLS-based EAP methods, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via a long "not after" timestamp in a client certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:55.041-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:51.049-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:06.991-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="freeradius2-python is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:94502"/>
          <criterion comment="freeradius2-unixODBC is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:94458"/>
          <criterion comment="freeradius2-krb5 is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:94169"/>
          <criterion comment="freeradius2 is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:94571"/>
          <criterion comment="freeradius2-perl is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:94644"/>
          <criterion comment="freeradius2-ldap is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:94574"/>
          <criterion comment="freeradius2-mysql is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:94514"/>
          <criterion comment="freeradius2-postgresql is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:94646"/>
          <criterion comment="freeradius2-utils is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:94456"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21297" version="55" class="patch">
      <metadata>
        <title>RHSA-2012:1323: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1323-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1323.html"/>
        <reference source="CESA" ref_id="CESA-2012:1323"/>
        <reference source="CVE" ref_id="CVE-2012-2319" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2319.html"/>
        <reference source="CVE" ref_id="CVE-2012-3412" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3412.html"/>
        <reference source="CVE" ref_id="CVE-2012-3430" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3430.html"/>
        <reference source="CVE" ref_id="CVE-2012-3510" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3510.html"/>
        <description>Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct.c in the Linux kernel before 2.6.19 allows local users to obtain potentially sensitive information from kernel memory or cause a denial of service (system crash) via a taskstats TASKSTATS_CMD_ATTR_PID command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:15.501-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:50.789-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:06.697-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:94523"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:94487"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:94547"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:93840"/>
          <criterion comment="kernel is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:94564"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:94421"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:94590"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:94480"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:94624"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:94500"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:94596"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:94605"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21291" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0311: ibutils security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>ibutils</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0311-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0311.html"/>
        <reference source="CVE" ref_id="CVE-2008-3277" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3277.html"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:36.179-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:50.394-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:06.262-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="ibutils-devel is earlier than 0:1.2-11.2.el5" test_ref="oval:org.mitre.oval:tst:92640"/>
          <criterion comment="ibutils is earlier than 0:1.2-11.2.el5" test_ref="oval:org.mitre.oval:tst:93033"/>
          <criterion comment="ibutils-libs is earlier than 0:1.2-11.2.el5" test_ref="oval:org.mitre.oval:tst:92082"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21290" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0717: bind97 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0717-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0717.html"/>
        <reference source="CESA" ref_id="CESA-2012:0717"/>
        <reference source="CVE" ref_id="CVE-2012-1033" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1033.html"/>
        <reference source="CVE" ref_id="CVE-2012-1667" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1667.html"/>
        <description>ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:04.534-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:50.302-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:06.115-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="bind97-devel is earlier than 32:9.7.0-10.P2.el5_8.1" test_ref="oval:org.mitre.oval:tst:93516"/>
          <criterion comment="bind97-utils is earlier than 32:9.7.0-10.P2.el5_8.1" test_ref="oval:org.mitre.oval:tst:93276"/>
          <criterion comment="bind97 is earlier than 32:9.7.0-10.P2.el5_8.1" test_ref="oval:org.mitre.oval:tst:93770"/>
          <criterion comment="bind97-chroot is earlier than 32:9.7.0-10.P2.el5_8.1" test_ref="oval:org.mitre.oval:tst:93759"/>
          <criterion comment="bind97-libs is earlier than 32:9.7.0-10.P2.el5_8.1" test_ref="oval:org.mitre.oval:tst:93713"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21288" version="94" class="patch">
      <metadata>
        <title>RHSA-2012:0103: squirrelmail security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>squirrelmail</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0103-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0103.html"/>
        <reference source="CESA" ref_id="CESA-2012:0103"/>
        <reference source="CVE" ref_id="CVE-2010-1637" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1637.html"/>
        <reference source="CVE" ref_id="CVE-2010-2813" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2813.html"/>
        <reference source="CVE" ref_id="CVE-2010-4554" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4554.html"/>
        <reference source="CVE" ref_id="CVE-2010-4555" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4555.html"/>
        <reference source="CVE" ref_id="CVE-2011-2023" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2023.html"/>
        <reference source="CVE" ref_id="CVE-2011-2752" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2752.html"/>
        <reference source="CVE" ref_id="CVE-2011-2753" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2753.html"/>
        <description>Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.21 and earlier allow remote attackers to hijack the authentication of unspecified victims via vectors involving (1) the empty trash implementation and (2) the Index Order (aka options_order) page, a different issue than CVE-2010-4555.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:04.915-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:49.907-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:05.505-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el5_7.13" test_ref="oval:org.mitre.oval:tst:92822"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el5.centos.13" test_ref="oval:org.mitre.oval:tst:94972"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21287" version="42" class="patch">
      <metadata>
        <title>RHSA-2012:0745: python security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>python</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0745-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0745.html"/>
        <reference source="CESA" ref_id="CESA-2012:0745"/>
        <reference source="CVE" ref_id="CVE-2011-4940" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4940.html"/>
        <reference source="CVE" ref_id="CVE-2011-4944" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4944.html"/>
        <reference source="CVE" ref_id="CVE-2012-1150" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1150.html"/>
        <description>Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:31.566-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:49.793-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:05.340-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="python-devel is earlier than 0:2.4.3-46.el5_8.2" test_ref="oval:org.mitre.oval:tst:93595"/>
          <criterion comment="python-libs is earlier than 0:2.4.3-46.el5_8.2" test_ref="oval:org.mitre.oval:tst:93717"/>
          <criterion comment="python is earlier than 0:2.4.3-46.el5_8.2" test_ref="oval:org.mitre.oval:tst:93483"/>
          <criterion comment="tkinter is earlier than 0:2.4.3-46.el5_8.2" test_ref="oval:org.mitre.oval:tst:93846"/>
          <criterion comment="python-tools is earlier than 0:2.4.3-46.el5_8.2" test_ref="oval:org.mitre.oval:tst:93654"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21285" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0327: subversion security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0327-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0327.html"/>
        <reference source="CESA" ref_id="CESA-2011:0327"/>
        <reference source="CVE" ref_id="CVE-2011-0715" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0715.html"/>
        <description>The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:31.944-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:49.716-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:05.224-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="subversion-devel is earlier than 0:1.6.11-7.el5_6.3" test_ref="oval:org.mitre.oval:tst:97284"/>
          <criterion comment="subversion is earlier than 0:1.6.11-7.el5_6.3" test_ref="oval:org.mitre.oval:tst:97381"/>
          <criterion comment="subversion-perl is earlier than 0:1.6.11-7.el5_6.3" test_ref="oval:org.mitre.oval:tst:97495"/>
          <criterion comment="subversion-ruby is earlier than 0:1.6.11-7.el5_6.3" test_ref="oval:org.mitre.oval:tst:97511"/>
          <criterion comment="subversion-javahl is earlier than 0:1.6.11-7.el5_6.3" test_ref="oval:org.mitre.oval:tst:97015"/>
          <criterion comment="mod_dav_svn is earlier than 0:1.6.11-7.el5_6.3" test_ref="oval:org.mitre.oval:tst:97509"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21283" version="117" class="patch">
      <metadata>
        <title>RHSA-2013:1823: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1823-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1823.html"/>
        <reference source="CESA" ref_id="CESA-2013:1823"/>
        <reference source="CVE" ref_id="CVE-2013-0772" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0772.html"/>
        <reference source="CVE" ref_id="CVE-2013-5609" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5609.html"/>
        <reference source="CVE" ref_id="CVE-2013-5612" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5612.html"/>
        <reference source="CVE" ref_id="CVE-2013-5613" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5613.html"/>
        <reference source="CVE" ref_id="CVE-2013-5614" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5614.html"/>
        <reference source="CVE" ref_id="CVE-2013-5616" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5616.html"/>
        <reference source="CVE" ref_id="CVE-2013-5618" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5618.html"/>
        <reference source="CVE" ref_id="CVE-2013-6671" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6671.html"/>
        <description>The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code via crafted use of JavaScript code for ordered list elements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:17.748-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:24.774-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:38.090-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21283 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:40.695-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:34.721-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:24.2.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:91943"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:24.2.0-2.el5.centos" test_ref="oval:org.mitre.oval:tst:91862"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:24.2.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:91932"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:24.2.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92056"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21282" version="185" class="patch">
      <metadata>
        <title>RHSA-2012:1089: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1089-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1089.html"/>
        <reference source="CESA" ref_id="CESA-2012:1089"/>
        <reference source="CVE" ref_id="CVE-2012-1948" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1948.html"/>
        <reference source="CVE" ref_id="CVE-2012-1951" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1951.html"/>
        <reference source="CVE" ref_id="CVE-2012-1952" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1952.html"/>
        <reference source="CVE" ref_id="CVE-2012-1953" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1953.html"/>
        <reference source="CVE" ref_id="CVE-2012-1954" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1954.html"/>
        <reference source="CVE" ref_id="CVE-2012-1955" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1955.html"/>
        <reference source="CVE" ref_id="CVE-2012-1957" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1957.html"/>
        <reference source="CVE" ref_id="CVE-2012-1958" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1958.html"/>
        <reference source="CVE" ref_id="CVE-2012-1959" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1959.html"/>
        <reference source="CVE" ref_id="CVE-2012-1961" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1961.html"/>
        <reference source="CVE" ref_id="CVE-2012-1962" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1962.html"/>
        <reference source="CVE" ref_id="CVE-2012-1963" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1963.html"/>
        <reference source="CVE" ref_id="CVE-2012-1964" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1964.html"/>
        <reference source="CVE" ref_id="CVE-2012-1967" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1967.html"/>
        <description>Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not properly implement the JavaScript sandbox utility, which allows remote attackers to execute arbitrary JavaScript code with improper privileges via a javascript: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:00.080-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:44.354-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:04.645-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.6-1.el5_8" test_ref="oval:org.mitre.oval:tst:93890"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.6-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94942"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:93836"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.6-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94863"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21281" version="59" class="patch">
      <metadata>
        <title>RHSA-2013:1449: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1449-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1449.html"/>
        <reference source="CESA" ref_id="CESA-2013:1449"/>
        <reference source="CVE" ref_id="CVE-2013-0333" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0333.html"/>
        <reference source="CVE" ref_id="CVE-2013-4299" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4299.html"/>
        <reference source="CVE" ref_id="CVE-2013-4345" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4345.html"/>
        <reference source="CVE" ref_id="CVE-2013-4368" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4368.html"/>
        <description>The outs instruction emulation in Xen 3.1.x, 4.2.x, 4.3.x, and earlier, when using FS: or GS: segment override, uses an uninitialized variable as a segment base, which allows local 64-bit PV guests to obtain sensitive information (hypervisor stack content) via unspecified vectors related to stale data in a segment register.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:07.100-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:24.521-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:37.879-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:91483"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:91315"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:91664"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:91863"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:91782"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:91745"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:91680"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:91896"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:91715"/>
          <criterion comment="kernel is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:91816"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:91778"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:91422"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21280" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0716: bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0716-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0716.html"/>
        <reference source="CESA" ref_id="CESA-2012:0716"/>
        <reference source="CVE" ref_id="CVE-2012-1033" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1033.html"/>
        <reference source="CVE" ref_id="CVE-2012-1667" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1667.html"/>
        <description>ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:00.188-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:44.166-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:04.492-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bind is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:93872"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:93808"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:93133"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:93803"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:93660"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:93455"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:93618"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:93794"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bind is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:93755"/>
            <criterion comment="bind-chroot is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:93619"/>
            <criterion comment="bind-sdb is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:93828"/>
            <criterion comment="bind-libs is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:93687"/>
            <criterion comment="bind-utils is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:93726"/>
            <criterion comment="bind-devel is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:93341"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21279" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0426: openssl security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0426-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0426.html"/>
        <reference source="CESA" ref_id="CESA-2012:0426"/>
        <reference source="CVE" ref_id="CVE-2012-0884" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0884.html"/>
        <reference source="CVE" ref_id="CVE-2012-1165" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1165.html"/>
        <description>The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:45.614-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:44.011-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:04.343-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:92404"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:93315"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:93324"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:93210"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:93212"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:92765"/>
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:93257"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21277" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1457: libgcrypt security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libgcrypt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1457-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1457.html"/>
        <reference source="CESA" ref_id="CESA-2013:1457"/>
        <reference source="CVE" ref_id="CVE-2013-4242" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4242.html"/>
        <description>GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:27.148-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:24.401-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:37.759-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libgcrypt-devel is earlier than 0:1.4.5-11.el6_4" test_ref="oval:org.mitre.oval:tst:91628"/>
            <criterion comment="libgcrypt is earlier than 0:1.4.5-11.el6_4" test_ref="oval:org.mitre.oval:tst:91830"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libgcrypt-devel is earlier than 0:1.4.4-7.el5_10" test_ref="oval:org.mitre.oval:tst:91601"/>
            <criterion comment="libgcrypt is earlier than 0:1.4.4-7.el5_10" test_ref="oval:org.mitre.oval:tst:91398"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21275" version="5" class="patch">
      <metadata>
        <title>RHSA-2011:0374: thunderbird security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0374-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0374.html"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

This erratum blacklists a small number of HTTPS certificates. (BZ#689430)

This update also fixes the following bug:

* The RHSA-2011:0312 and RHSA-2011:0311 updates introduced a regression,
preventing some Java content and plug-ins written in Java from loading.
With this update, the Java content and plug-ins work as expected.
(BZ#683076)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:26.369-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:43.680-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:03.916-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21275 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:42.934-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:34.611-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.24-15.el5_6" test_ref="oval:org.mitre.oval:tst:97616"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="thunderbird is earlier than 0:3.1.9-3.el6_0" test_ref="oval:org.mitre.oval:tst:97486"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21273" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0290: java-1.6.0-ibm security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0290-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0290.html"/>
        <reference source="CVE" ref_id="CVE-2010-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4476.html"/>
        <description>The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:52.350-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:43.479-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:03.647-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:97234"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:97396"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:97362"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:97439"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:97383"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:97504"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:97068"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:96560"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:97259"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:96596"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:97479"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:97343"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:97548"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:97462"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:97444"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21271" version="68" class="patch">
      <metadata>
        <title>RHSA-2012:1045: php security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1045-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1045.html"/>
        <reference source="CESA" ref_id="CESA-2012:1045"/>
        <reference source="CVE" ref_id="CVE-2011-4153" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4153.html"/>
        <reference source="CVE" ref_id="CVE-2012-0057" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0057.html"/>
        <reference source="CVE" ref_id="CVE-2012-0789" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0789.html"/>
        <reference source="CVE" ref_id="CVE-2012-1172" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1172.html"/>
        <reference source="CVE" ref_id="CVE-2012-2336" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2336.html"/>
        <description>sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to cause a denial of service (resource consumption) by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'T' case.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:17.140-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:43.197-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:03.295-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="php-ncurses is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:93661"/>
          <criterion comment="php-gd is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:94026"/>
          <criterion comment="php is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:94078"/>
          <criterion comment="php-ldap is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:93996"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:93904"/>
          <criterion comment="php-mbstring is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:93992"/>
          <criterion comment="php-cli is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:93957"/>
          <criterion comment="php-mysql is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:93990"/>
          <criterion comment="php-devel is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:93548"/>
          <criterion comment="php-dba is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:94037"/>
          <criterion comment="php-xml is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:93107"/>
          <criterion comment="php-odbc is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:93786"/>
          <criterion comment="php-snmp is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:93534"/>
          <criterion comment="php-common is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:93593"/>
          <criterion comment="php-imap is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:93669"/>
          <criterion comment="php-soap is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:93852"/>
          <criterion comment="php-pgsql is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:93774"/>
          <criterion comment="php-pdo is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:93935"/>
          <criterion comment="php-bcmath is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:94017"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21269" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0370: xen security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0370-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0370.html"/>
        <reference source="CVE" ref_id="CVE-2012-0029" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0029.html"/>
        <description>Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS users to cause a denial of service (QEMU crash) and possibly execute arbitrary code via crafted legacy mode packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:16.186-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:43.113-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:03.191-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="xen is earlier than 0:3.0.3-135.el5_8.2" test_ref="oval:org.mitre.oval:tst:92092"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-135.el5_8.2" test_ref="oval:org.mitre.oval:tst:92350"/>
          <criterion comment="xen-libs is earlier than 0:3.0.3-135.el5_8.2" test_ref="oval:org.mitre.oval:tst:92815"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21268" version="302" class="patch">
      <metadata>
        <title>RHSA-2012:1211: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1211-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1211.html"/>
        <reference source="CESA" ref_id="CESA-2012:1211"/>
        <reference source="CVE" ref_id="CVE-2012-1970" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1970.html"/>
        <reference source="CVE" ref_id="CVE-2012-1972" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1972.html"/>
        <reference source="CVE" ref_id="CVE-2012-1973" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1973.html"/>
        <reference source="CVE" ref_id="CVE-2012-1974" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1974.html"/>
        <reference source="CVE" ref_id="CVE-2012-1975" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1975.html"/>
        <reference source="CVE" ref_id="CVE-2012-1976" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1976.html"/>
        <reference source="CVE" ref_id="CVE-2012-3956" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3956.html"/>
        <reference source="CVE" ref_id="CVE-2012-3957" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3957.html"/>
        <reference source="CVE" ref_id="CVE-2012-3958" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3958.html"/>
        <reference source="CVE" ref_id="CVE-2012-3959" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3959.html"/>
        <reference source="CVE" ref_id="CVE-2012-3960" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3960.html"/>
        <reference source="CVE" ref_id="CVE-2012-3961" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3961.html"/>
        <reference source="CVE" ref_id="CVE-2012-3962" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3962.html"/>
        <reference source="CVE" ref_id="CVE-2012-3963" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3963.html"/>
        <reference source="CVE" ref_id="CVE-2012-3964" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3964.html"/>
        <reference source="CVE" ref_id="CVE-2012-3966" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3966.html"/>
        <reference source="CVE" ref_id="CVE-2012-3967" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3967.html"/>
        <reference source="CVE" ref_id="CVE-2012-3968" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3968.html"/>
        <reference source="CVE" ref_id="CVE-2012-3969" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3969.html"/>
        <reference source="CVE" ref_id="CVE-2012-3970" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3970.html"/>
        <reference source="CVE" ref_id="CVE-2012-3972" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3972.html"/>
        <reference source="CVE" ref_id="CVE-2012-3978" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3978.html"/>
        <reference source="CVE" ref_id="CVE-2012-3980" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3980.html"/>
        <description>The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that injects this code and triggers an eval operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:41.791-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:42.326-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:02.376-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.7-1.el5_8" test_ref="oval:org.mitre.oval:tst:94373"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.7-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94599"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:94386"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.7-1.el6.centos" test_ref="oval:org.mitre.oval:tst:95015"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21267" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1149: sudo security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1149-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1149.html"/>
        <reference source="CESA" ref_id="CESA-2012:1149"/>
        <reference source="CVE" ref_id="CVE-2012-3440" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3440.html"/>
        <description>A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on the /var/tmp/nsswitch.conf.bak temporary file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:22.746-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:42.229-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:02.276-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="sudo is earlier than 0:1.7.2p1-14.el5_8.2" test_ref="oval:org.mitre.oval:tst:94196"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21264" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0468: libtiff security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0468-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0468.html"/>
        <reference source="CESA" ref_id="CESA-2012:0468"/>
        <reference source="CVE" ref_id="CVE-2012-1173" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1173.html"/>
        <description>Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9.4 allow remote attackers to execute arbitrary code via a crafted tile size in a TIFF file, which is not properly handled by the (1) gtTileSeparate or (2) gtStripSeparate function, leading to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:35.188-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:42.074-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:02.118-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libtiff is earlier than 0:3.8.2-14.el5_8" test_ref="oval:org.mitre.oval:tst:93059"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-14.el5_8" test_ref="oval:org.mitre.oval:tst:93328"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libtiff is earlier than 0:3.9.4-5.el6_2" test_ref="oval:org.mitre.oval:tst:93286"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-5.el6_2" test_ref="oval:org.mitre.oval:tst:93196"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-5.el6_2" test_ref="oval:org.mitre.oval:tst:92360"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21262" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:1778: gimp security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>gimp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1778-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1778.html"/>
        <reference source="CESA" ref_id="CESA-2013:1778"/>
        <reference source="CVE" ref_id="CVE-2012-5576" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5576.html"/>
        <reference source="CVE" ref_id="CVE-2013-1913" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1913.html"/>
        <reference source="CVE" ref_id="CVE-2013-1978" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1978.html"/>
        <description>Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:13.507-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:24.135-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:37.474-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="gimp-libs is earlier than 2:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:91590"/>
            <criterion comment="gimp-devel is earlier than 2:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:91702"/>
            <criterion comment="gimp is earlier than 2:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:91761"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="gimp-libs is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:91665"/>
            <criterion comment="gimp-devel-tools is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:91759"/>
            <criterion comment="gimp-devel is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:91897"/>
            <criterion comment="gimp is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:91877"/>
            <criterion comment="gimp-help-browser is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:91673"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21259" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0013: wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0013-02" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0013.html"/>
        <reference source="CVE" ref_id="CVE-2010-4538" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4538.html"/>
        <description>Buffer overflow in the sect_enttec_dmx_da function in epan/dissectors/packet-enttec.c in Wireshark 1.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ENTTEC DMX packet with Run Length Encoding (RLE) compression.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:21.974-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:41.864-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:01.908-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="wireshark is earlier than 0:1.0.15-1.el5_5.3" test_ref="oval:org.mitre.oval:tst:96536"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.15-1.el5_5.3" test_ref="oval:org.mitre.oval:tst:96857"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="wireshark is earlier than 0:1.2.13-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:96885"/>
            <criterion comment="wireshark-devel is earlier than 0:1.2.13-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:96415"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.2.13-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:96853"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21255" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0155: java-1.4.2-ibm security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.4.2-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0155-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0155.html"/>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html"/>
        <description>The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:56.304-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:41.538-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:01.599-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99029"/>
          <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99224"/>
          <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99154"/>
          <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99235"/>
          <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98801"/>
          <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:99213"/>
          <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98839"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21253" version="94" class="patch">
      <metadata>
        <title>RHSA-2010:0360: wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 5</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0360-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0360.html"/>
        <reference source="CESA" ref_id="CESA-2010:0360"/>
        <reference source="CVE" ref_id="CVE-2009-2560" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2560.html"/>
        <reference source="CVE" ref_id="CVE-2009-2562" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2562.html"/>
        <reference source="CVE" ref_id="CVE-2009-2563" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2563.html"/>
        <reference source="CVE" ref_id="CVE-2009-3550" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3550.html"/>
        <reference source="CVE" ref_id="CVE-2009-3829" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3829.html"/>
        <reference source="CVE" ref_id="CVE-2009-4377" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4377.html"/>
        <reference source="CVE" ref_id="CVE-2010-0304" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0304.html"/>
        <description>Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the dissect_getaddrsbyname_request function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:35.310-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:41.189-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:01.188-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="wireshark is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:99264"/>
          <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:99415"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21251" version="6" class="patch">
      <metadata>
        <title>RHSA-2014:0016: gnupg security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gnupg</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0016-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0016.html"/>
        <reference source="CESA" ref_id="CESA-2014:0016"/>
        <reference source="CVE" ref_id="CVE-2013-4576" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4576.html"/>
        <description>GnuPG 1.x before 1.4.16 generates RSA keys using sequences of introductions with certain patterns that introduce a side channel, which allows physically proximate attackers to extract RSA keys via a chosen-ciphertext attack and acoustic cryptanalysis during decryption. NOTE: applications are not typically expected to protect themselves from acoustic side-channel attacks, since this is arguably the responsibility of the physical device. Accordingly, issues of this type would not normally receive a CVE identifier. However, for this issue, the developer has specified a security policy in which GnuPG should offer side-channel resistance, and developer-specified security-policy violations are within the scope of CVE.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:58:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:42:31.984-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:40.809-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:00.899-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21251 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:41.923-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:32.801-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="gnupg is earlier than 0:1.4.5-18.el5_10.1" test_ref="oval:org.mitre.oval:tst:98929"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21250" version="42" class="patch">
      <metadata>
        <title>RHSA-2012:0428: gnutls security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0428-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0428.html"/>
        <reference source="CESA" ref_id="CESA-2012:0428"/>
        <reference source="CVE" ref_id="CVE-2011-4128" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4128.html"/>
        <reference source="CVE" ref_id="CVE-2012-1569" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1569.html"/>
        <reference source="CVE" ref_id="CVE-2012-1573" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1573.html"/>
        <description>gnutls_cipher.c in libgnutls in GnuTLS before 2.12.17 and 3.x before 3.0.15 does not properly handle data encrypted with a block cipher, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) via a crafted record, as demonstrated by a crafted GenericBlockCipher structure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:37.523-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:40.684-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:00.674-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="gnutls is earlier than 0:1.4.1-7.el5_8.2" test_ref="oval:org.mitre.oval:tst:92755"/>
          <criterion comment="gnutls-devel is earlier than 0:1.4.1-7.el5_8.2" test_ref="oval:org.mitre.oval:tst:93213"/>
          <criterion comment="gnutls-utils is earlier than 0:1.4.1-7.el5_8.2" test_ref="oval:org.mitre.oval:tst:93335"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21242" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1061: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1061-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1061.html"/>
        <reference source="CESA" ref_id="CESA-2012:1061"/>
        <reference source="CVE" ref_id="CVE-2012-3375" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3375.html"/>
        <description>The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 does not properly handle ELOOP errors in EPOLL_CTL_ADD operations, which allows local users to cause a denial of service (file-descriptor consumption and system crash) via a crafted application that attempts to create a circular epoll dependency.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1083.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:14.844-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:40.252-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:00.241-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:93919"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:94134"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:93818"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:93989"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:93620"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:94116"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:94100"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:93406"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:94107"/>
          <criterion comment="kernel is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:93727"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:94138"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:93740"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21241" version="229" class="patch">
      <metadata>
        <title>RHSA-2013:0855: java-1.5.0-ibm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0855-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0855.html"/>
        <reference source="CVE" ref_id="CVE-2013-0169" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0169.html"/>
        <reference source="CVE" ref_id="CVE-2013-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0401.html"/>
        <reference source="CVE" ref_id="CVE-2013-1491" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1491.html"/>
        <reference source="CVE" ref_id="CVE-2013-1537" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1537.html"/>
        <reference source="CVE" ref_id="CVE-2013-1557" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1557.html"/>
        <reference source="CVE" ref_id="CVE-2013-1569" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1569.html"/>
        <reference source="CVE" ref_id="CVE-2013-2383" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2383.html"/>
        <reference source="CVE" ref_id="CVE-2013-2384" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2384.html"/>
        <reference source="CVE" ref_id="CVE-2013-2394" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2394.html"/>
        <reference source="CVE" ref_id="CVE-2013-2417" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2417.html"/>
        <reference source="CVE" ref_id="CVE-2013-2419" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2419.html"/>
        <reference source="CVE" ref_id="CVE-2013-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2420.html"/>
        <reference source="CVE" ref_id="CVE-2013-2424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2424.html"/>
        <reference source="CVE" ref_id="CVE-2013-2429" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2429.html"/>
        <reference source="CVE" ref_id="CVE-2013-2430" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2430.html"/>
        <reference source="CVE" ref_id="CVE-2013-2432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2432.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2394 and CVE-2013-1491.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:44.309-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:22.801-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:36.268-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21241 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:30.082-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:57.296-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137691"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137614"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137026"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137722"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:136824"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137726"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137814"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137453"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91156"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91293"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91092"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90316"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91259"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90805"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91237"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21240" version="551" class="patch">
      <metadata>
        <title>RHSA-2013:1508: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1508-04" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1508.html"/>
        <reference source="CVE" ref_id="CVE-2013-3829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3829.html"/>
        <reference source="CVE" ref_id="CVE-2013-4041" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4041.html"/>
        <reference source="CVE" ref_id="CVE-2013-5372" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5372.html"/>
        <reference source="CVE" ref_id="CVE-2013-5375" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5375.html"/>
        <reference source="CVE" ref_id="CVE-2013-5457" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5457.html"/>
        <reference source="CVE" ref_id="CVE-2013-5772" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5772.html"/>
        <reference source="CVE" ref_id="CVE-2013-5774" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5774.html"/>
        <reference source="CVE" ref_id="CVE-2013-5776" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5776.html"/>
        <reference source="CVE" ref_id="CVE-2013-5778" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5778.html"/>
        <reference source="CVE" ref_id="CVE-2013-5780" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5780.html"/>
        <reference source="CVE" ref_id="CVE-2013-5782" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5782.html"/>
        <reference source="CVE" ref_id="CVE-2013-5783" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5783.html"/>
        <reference source="CVE" ref_id="CVE-2013-5784" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5784.html"/>
        <reference source="CVE" ref_id="CVE-2013-5787" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5787.html"/>
        <reference source="CVE" ref_id="CVE-2013-5789" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5789.html"/>
        <reference source="CVE" ref_id="CVE-2013-5797" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5797.html"/>
        <reference source="CVE" ref_id="CVE-2013-5801" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5801.html"/>
        <reference source="CVE" ref_id="CVE-2013-5802" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5802.html"/>
        <reference source="CVE" ref_id="CVE-2013-5803" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5803.html"/>
        <reference source="CVE" ref_id="CVE-2013-5804" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5804.html"/>
        <reference source="CVE" ref_id="CVE-2013-5809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5809.html"/>
        <reference source="CVE" ref_id="CVE-2013-5812" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5812.html"/>
        <reference source="CVE" ref_id="CVE-2013-5814" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5814.html"/>
        <reference source="CVE" ref_id="CVE-2013-5817" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5817.html"/>
        <reference source="CVE" ref_id="CVE-2013-5818" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5818.html"/>
        <reference source="CVE" ref_id="CVE-2013-5819" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5819.html"/>
        <reference source="CVE" ref_id="CVE-2013-5820" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5820.html"/>
        <reference source="CVE" ref_id="CVE-2013-5823" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5823.html"/>
        <reference source="CVE" ref_id="CVE-2013-5824" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5824.html"/>
        <reference source="CVE" ref_id="CVE-2013-5825" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5825.html"/>
        <reference source="CVE" ref_id="CVE-2013-5829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5829.html"/>
        <reference source="CVE" ref_id="CVE-2013-5830" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5830.html"/>
        <reference source="CVE" ref_id="CVE-2013-5831" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5831.html"/>
        <reference source="CVE" ref_id="CVE-2013-5832" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5832.html"/>
        <reference source="CVE" ref_id="CVE-2013-5840" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5840.html"/>
        <reference source="CVE" ref_id="CVE-2013-5842" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5842.html"/>
        <reference source="CVE" ref_id="CVE-2013-5843" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5843.html"/>
        <reference source="CVE" ref_id="CVE-2013-5848" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5848.html"/>
        <reference source="CVE" ref_id="CVE-2013-5849" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5849.html"/>
        <reference source="CVE" ref_id="CVE-2013-5850" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5850.html"/>
        <reference source="CVE" ref_id="CVE-2013-5851" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5851.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via vectors related to JAXP.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:09.322-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:21.387-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:35.637-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21240 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:27.608-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:53.828-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.15.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137595"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.15.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137823"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.15.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137810"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.15.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137816"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.15.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137378"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.15.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137597"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.15.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137559"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.15.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:136830"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91425"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91900"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91281"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91817"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91073"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91412"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91719"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21239" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1081: sudo security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1081-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1081.html"/>
        <reference source="CESA" ref_id="CESA-2012:1081"/>
        <reference source="CVE" ref_id="CVE-2012-2337" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2337.html"/>
        <description>sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:23.455-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:40.148-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:00.148-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="sudo is earlier than 0:1.7.2p1-14.el5_8" test_ref="oval:org.mitre.oval:tst:93943"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="sudo is earlier than 0:1.7.4p5-12.el6_3" test_ref="oval:org.mitre.oval:tst:93880"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21237" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0258: pam_krb5 security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>pam_krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0258-04" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0258.html"/>
        <reference source="CVE" ref_id="CVE-2009-1384" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1384.html"/>
        <description>pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:15.646-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:40.063-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:00.054-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="pam_krb5 is earlier than 0:2.2.14-15" test_ref="oval:org.mitre.oval:tst:99036"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21234" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1213: gdm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gdm</product>
          <product>initscripts</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1213-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1213.html"/>
        <reference source="CESA" ref_id="CESA-2013:1213"/>
        <reference source="CVE" ref_id="CVE-2013-4169" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4169.html"/>
        <description>GNOME Display Manager (gdm) before 2.21.1 allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:32.674-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:20.762-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:35.171-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="initscripts is earlier than 0:8.45.42-2.el5_9.1" test_ref="oval:org.mitre.oval:tst:91657"/>
            <criterion comment="gdm is earlier than 1:2.16.0-59.el5_9.1" test_ref="oval:org.mitre.oval:tst:91465"/>
            <criterion comment="gdm-docs is earlier than 1:2.16.0-59.el5_9.1" test_ref="oval:org.mitre.oval:tst:90803"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="initscripts is earlier than 0:8.45.42-2.el5.centos.1" test_ref="oval:org.mitre.oval:tst:92132"/>
            <criterion comment="gdm is earlier than 1:2.16.0-59.el5.centos.1" test_ref="oval:org.mitre.oval:tst:91906"/>
            <criterion comment="gdm-docs is earlier than 1:2.16.0-59.el5.centos.1" test_ref="oval:org.mitre.oval:tst:91986"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21233" version="81" class="patch">
      <metadata>
        <title>RHSA-2012:1540: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1540-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1540.html"/>
        <reference source="CESA" ref_id="CESA-2012:1540"/>
        <reference source="CVE" ref_id="CVE-2012-2372" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2372.html"/>
        <reference source="CVE" ref_id="CVE-2012-3552" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3552.html"/>
        <reference source="CVE" ref_id="CVE-2012-4508" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4508.html"/>
        <reference source="CVE" ref_id="CVE-2012-4535" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4535.html"/>
        <reference source="CVE" ref_id="CVE-2012-4537" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4537.html"/>
        <reference source="CVE" ref_id="CVE-2012-5513" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5513.html"/>
        <description>The XENMEM_exchange handler in Xen 4.2 and earlier does not properly check the memory address, which allows local PV guest OS administrators to cause a denial of service (crash) or possibly gain privileges via unspecified vectors that overwrite memory in the hypervisor reserved range.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:27.600-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:39.732-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:59.483-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:94540"/>
          <criterion comment="kernel is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:94826"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:94263"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:94910"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:94949"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:94294"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:94948"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:94681"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:94767"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:94513"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:94466"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:94915"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21231" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1364: bind97 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1364-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1364.html"/>
        <reference source="CESA" ref_id="CESA-2012:1364"/>
        <reference source="CVE" ref_id="CVE-2012-5166" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5166.html"/>
        <description>ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:50.794-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:39.635-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:59.320-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="bind97 is earlier than 32:9.7.0-10.P2.el5_8.4" test_ref="oval:org.mitre.oval:tst:94628"/>
          <criterion comment="bind97-devel is earlier than 32:9.7.0-10.P2.el5_8.4" test_ref="oval:org.mitre.oval:tst:94686"/>
          <criterion comment="bind97-utils is earlier than 32:9.7.0-10.P2.el5_8.4" test_ref="oval:org.mitre.oval:tst:94680"/>
          <criterion comment="bind97-chroot is earlier than 32:9.7.0-10.P2.el5_8.4" test_ref="oval:org.mitre.oval:tst:94751"/>
          <criterion comment="bind97-libs is earlier than 32:9.7.0-10.P2.el5_8.4" test_ref="oval:org.mitre.oval:tst:94727"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21230" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0085: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0085-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0085.html"/>
        <reference source="CESA" ref_id="CESA-2012:0085"/>
        <reference source="CVE" ref_id="CVE-2011-3670" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3670.html"/>
        <reference source="CVE" ref_id="CVE-2012-0442" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0442.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:42.545-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:39.514-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:59.150-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.24-28.el5_7" test_ref="oval:org.mitre.oval:tst:92685"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.24-28.el5.centos" test_ref="oval:org.mitre.oval:tst:94565"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21226" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1452: vino security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>vino</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1452-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1452.html"/>
        <reference source="CESA" ref_id="CESA-2013:1452"/>
        <reference source="CVE" ref_id="CVE-2013-5745" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5745.html"/>
        <description>The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection to close during authentication, which allows remote attackers to cause a denial of service (infinite loop, CPU and disk consumption) via multiple crafted requests during authentication.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:34.240-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:20.531-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:34.929-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criterion comment="vino is earlier than 0:2.28.1-9.el6_4" test_ref="oval:org.mitre.oval:tst:91451"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="vino is earlier than 0:2.13.5-10.el5_10" test_ref="oval:org.mitre.oval:tst:91446"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21223" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0168: httpd security and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0168-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0168.html"/>
        <reference source="CESA" ref_id="CESA-2010:0168"/>
        <reference source="CVE" ref_id="CVE-2010-0408" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0408.html"/>
        <reference source="CVE" ref_id="CVE-2010-0434" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0434.html"/>
        <description>The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:44.406-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:39.266-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:58.857-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="httpd-manual is earlier than 0:2.2.3-31.el5_4.4" test_ref="oval:org.mitre.oval:tst:98959"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.3-31.el5_4.4" test_ref="oval:org.mitre.oval:tst:99269"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.3-31.el5_4.4" test_ref="oval:org.mitre.oval:tst:98588"/>
          <criterion comment="httpd is earlier than 0:2.2.3-31.el5_4.4" test_ref="oval:org.mitre.oval:tst:99078"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21222" version="409" class="patch">
      <metadata>
        <title>RHSA-2013:0958: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0958-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0958.html"/>
        <reference source="CESA" ref_id="CESA-2013:0958"/>
        <reference source="CVE" ref_id="CVE-2013-1500" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1500.html"/>
        <reference source="CVE" ref_id="CVE-2013-1571" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1571.html"/>
        <reference source="CVE" ref_id="CVE-2013-2407" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2407.html"/>
        <reference source="CVE" ref_id="CVE-2013-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2412.html"/>
        <reference source="CVE" ref_id="CVE-2013-2443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2443.html"/>
        <reference source="CVE" ref_id="CVE-2013-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2444.html"/>
        <reference source="CVE" ref_id="CVE-2013-2445" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2445.html"/>
        <reference source="CVE" ref_id="CVE-2013-2446" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2446.html"/>
        <reference source="CVE" ref_id="CVE-2013-2447" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2447.html"/>
        <reference source="CVE" ref_id="CVE-2013-2448" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2448.html"/>
        <reference source="CVE" ref_id="CVE-2013-2449" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2449.html"/>
        <reference source="CVE" ref_id="CVE-2013-2450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2450.html"/>
        <reference source="CVE" ref_id="CVE-2013-2452" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2452.html"/>
        <reference source="CVE" ref_id="CVE-2013-2453" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2453.html"/>
        <reference source="CVE" ref_id="CVE-2013-2454" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2454.html"/>
        <reference source="CVE" ref_id="CVE-2013-2455" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2455.html"/>
        <reference source="CVE" ref_id="CVE-2013-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2456.html"/>
        <reference source="CVE" ref_id="CVE-2013-2457" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2457.html"/>
        <reference source="CVE" ref_id="CVE-2013-2458" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2458.html"/>
        <reference source="CVE" ref_id="CVE-2013-2459" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2459.html"/>
        <reference source="CVE" ref_id="CVE-2013-2460" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2460.html"/>
        <reference source="CVE" ref_id="CVE-2013-2461" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2461.html"/>
        <reference source="CVE" ref_id="CVE-2013-2463" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2463.html"/>
        <reference source="CVE" ref_id="CVE-2013-2465" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2465.html"/>
        <reference source="CVE" ref_id="CVE-2013-2469" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2469.html"/>
        <reference source="CVE" ref_id="CVE-2013-2470" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2470.html"/>
        <reference source="CVE" ref_id="CVE-2013-2471" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2471.html"/>
        <reference source="CVE" ref_id="CVE-2013-2472" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2472.html"/>
        <reference source="CVE" ref_id="CVE-2013-2473" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2473.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect ByteBandedRaster size checks" in 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:38.794-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:20.210-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:34.591-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.25-2.3.10.4.el5_9" test_ref="oval:org.mitre.oval:tst:90677"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.25-2.3.10.4.el5_9" test_ref="oval:org.mitre.oval:tst:90519"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.25-2.3.10.4.el5_9" test_ref="oval:org.mitre.oval:tst:91406"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.25-2.3.10.4.el5_9" test_ref="oval:org.mitre.oval:tst:91415"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.25-2.3.10.4.el5_9" test_ref="oval:org.mitre.oval:tst:90759"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21220" version="159" class="patch">
      <metadata>
        <title>RHSA-2012:0516: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0516-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0516.html"/>
        <reference source="CESA" ref_id="CESA-2012:0516"/>
        <reference source="CVE" ref_id="CVE-2011-3062" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3062.html"/>
        <reference source="CVE" ref_id="CVE-2012-0467" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0467.html"/>
        <reference source="CVE" ref_id="CVE-2012-0468" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0468.html"/>
        <reference source="CVE" ref_id="CVE-2012-0469" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0469.html"/>
        <reference source="CVE" ref_id="CVE-2012-0470" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0470.html"/>
        <reference source="CVE" ref_id="CVE-2012-0471" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0471.html"/>
        <reference source="CVE" ref_id="CVE-2012-0472" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0472.html"/>
        <reference source="CVE" ref_id="CVE-2012-0473" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0473.html"/>
        <reference source="CVE" ref_id="CVE-2012-0474" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0474.html"/>
        <reference source="CVE" ref_id="CVE-2012-0477" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0477.html"/>
        <reference source="CVE" ref_id="CVE-2012-0478" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0478.html"/>
        <reference source="CVE" ref_id="CVE-2012-0479" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0479.html"/>
        <description>Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to spoof the address bar via an https URL for invalid (1) RSS or (2) Atom XML content.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:37.162-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:38.802-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:58.410-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:93012"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.4-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94095"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:93057"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.4-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94905"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21219" version="495" class="patch">
      <metadata>
        <title>RHSA-2013:1059: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1059-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1059.html"/>
        <reference source="CVE" ref_id="CVE-2013-1500" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1500.html"/>
        <reference source="CVE" ref_id="CVE-2013-1571" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1571.html"/>
        <reference source="CVE" ref_id="CVE-2013-2407" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2407.html"/>
        <reference source="CVE" ref_id="CVE-2013-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2412.html"/>
        <reference source="CVE" ref_id="CVE-2013-2437" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2437.html"/>
        <reference source="CVE" ref_id="CVE-2013-2442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2442.html"/>
        <reference source="CVE" ref_id="CVE-2013-2443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2443.html"/>
        <reference source="CVE" ref_id="CVE-2013-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2444.html"/>
        <reference source="CVE" ref_id="CVE-2013-2446" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2446.html"/>
        <reference source="CVE" ref_id="CVE-2013-2447" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2447.html"/>
        <reference source="CVE" ref_id="CVE-2013-2448" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2448.html"/>
        <reference source="CVE" ref_id="CVE-2013-2450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2450.html"/>
        <reference source="CVE" ref_id="CVE-2013-2451" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2451.html"/>
        <reference source="CVE" ref_id="CVE-2013-2452" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2452.html"/>
        <reference source="CVE" ref_id="CVE-2013-2453" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2453.html"/>
        <reference source="CVE" ref_id="CVE-2013-2454" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2454.html"/>
        <reference source="CVE" ref_id="CVE-2013-2455" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2455.html"/>
        <reference source="CVE" ref_id="CVE-2013-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2456.html"/>
        <reference source="CVE" ref_id="CVE-2013-2457" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2457.html"/>
        <reference source="CVE" ref_id="CVE-2013-2459" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2459.html"/>
        <reference source="CVE" ref_id="CVE-2013-2463" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2463.html"/>
        <reference source="CVE" ref_id="CVE-2013-2464" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2464.html"/>
        <reference source="CVE" ref_id="CVE-2013-2465" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2465.html"/>
        <reference source="CVE" ref_id="CVE-2013-2466" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2466.html"/>
        <reference source="CVE" ref_id="CVE-2013-2468" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2468.html"/>
        <reference source="CVE" ref_id="CVE-2013-2469" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2469.html"/>
        <reference source="CVE" ref_id="CVE-2013-2470" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2470.html"/>
        <reference source="CVE" ref_id="CVE-2013-2471" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2471.html"/>
        <reference source="CVE" ref_id="CVE-2013-2472" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2472.html"/>
        <reference source="CVE" ref_id="CVE-2013-2473" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2473.html"/>
        <reference source="CVE" ref_id="CVE-2013-3009" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3009.html"/>
        <reference source="CVE" ref_id="CVE-2013-3011" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3011.html"/>
        <reference source="CVE" ref_id="CVE-2013-3012" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3012.html"/>
        <reference source="CVE" ref_id="CVE-2013-3743" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3743.html"/>
        <reference source="CVE" ref_id="CVE-2013-4002" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4002.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 allows remote attackers to affect availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:36.803-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:18.917-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:34.183-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21219 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:19.257-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:51.124-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.14.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137369"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.14.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137731"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.14.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137370"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.14.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137083"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.14.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137748"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.14.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137661"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.14.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137754"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.14.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137651"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91292"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91414"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91096"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91508"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91175"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91161"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91234"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21216" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0883: gnutls security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0883-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0883.html"/>
        <reference source="CESA" ref_id="CESA-2013:0883"/>
        <reference source="CVE" ref_id="CVE-2013-2116" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2116.html"/>
        <description>The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length.  NOTE: this might be due to an incorrect fix for CVE-2013-0169.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:05.577-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:18.785-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:34.054-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="gnutls is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:90322"/>
            <criterion comment="gnutls-devel is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:91153"/>
            <criterion comment="gnutls-utils is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:90343"/>
            <criterion comment="gnutls-guile is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:91149"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="gnutls is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:91155"/>
            <criterion comment="gnutls-devel is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:91306"/>
            <criterion comment="gnutls-utils is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:91116"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21214" version="148" class="patch">
      <metadata>
        <title>RHSA-2011:0310: firefox security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0310-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0310.html"/>
        <reference source="CVE" ref_id="CVE-2010-1585" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1585.html"/>
        <reference source="CVE" ref_id="CVE-2011-0051" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0051.html"/>
        <reference source="CVE" ref_id="CVE-2011-0053" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0053.html"/>
        <reference source="CVE" ref_id="CVE-2011-0054" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0054.html"/>
        <reference source="CVE" ref_id="CVE-2011-0055" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0055.html"/>
        <reference source="CVE" ref_id="CVE-2011-0056" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0056.html"/>
        <reference source="CVE" ref_id="CVE-2011-0057" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0057.html"/>
        <reference source="CVE" ref_id="CVE-2011-0058" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0058.html"/>
        <reference source="CVE" ref_id="CVE-2011-0059" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0059.html"/>
        <reference source="CVE" ref_id="CVE-2011-0061" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0061.html"/>
        <reference source="CVE" ref_id="CVE-2011-0062" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0062.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.6.x before 3.6.14 and Thunderbird 3.1.x before 3.1.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:10.167-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:38.350-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:57.940-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21214 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:18.319-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:49.916-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.14-4.el5_6" test_ref="oval:org.mitre.oval:tst:137752"/>
            <criterion comment="firefox is earlier than 0:3.6.14-4.el5_6" test_ref="oval:org.mitre.oval:tst:137866"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.14-4.el5_6" test_ref="oval:org.mitre.oval:tst:137487"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:3.6.14-4.el6_0" test_ref="oval:org.mitre.oval:tst:97514"/>
            <criterion comment="firefox-debuginfo is earlier than 0:3.6.14-4.el6_0" test_ref="oval:org.mitre.oval:tst:137768"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.14-3.el6_0" test_ref="oval:org.mitre.oval:tst:97205"/>
            <criterion comment="xulrunner-debuginfo is earlier than 0:1.9.2.14-3.el6_0" test_ref="oval:org.mitre.oval:tst:137542"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.14-3.el6_0" test_ref="oval:org.mitre.oval:tst:97443"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21210" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:1292: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1292-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1292.html"/>
        <reference source="CESA" ref_id="CESA-2013:1292"/>
        <reference source="CVE" ref_id="CVE-2012-3511" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3511.html"/>
        <reference source="CVE" ref_id="CVE-2013-2141" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2141.html"/>
        <reference source="CVE" ref_id="CVE-2013-4162" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4162.html"/>
        <description>The udp_v6_push_pending_frames function in net/ipv6/udp.c in the IPv6 implementation in the Linux kernel through 3.10.3 makes an incorrect function call for pending data, which allows local users to cause a denial of service (BUG and system crash) via a crafted application that uses the UDP_CORK option in a setsockopt system call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:54.862-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:18.320-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:33.701-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:91687"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:91697"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:91267"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:91114"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:91742"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:91279"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:90766"/>
          <criterion comment="kernel is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:91704"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:91142"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:91329"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:91668"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:91342"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21206" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:1806: samba and samba3x security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1806-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1806.html"/>
        <reference source="CESA" ref_id="CESA-2013:1806"/>
        <reference source="CVE" ref_id="CVE-2013-4408" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4408.html"/>
        <reference source="CVE" ref_id="CVE-2013-4475" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4475.html"/>
        <description>Samba 3.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:29.692-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:17.804-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:33.480-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba3x is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:91989"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:91717"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:91982"/>
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:91851"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:91905"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:91785"/>
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:91820"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:91804"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba-common is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91929"/>
            <criterion comment="samba is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91999"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91962"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91864"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91917"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91457"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91741"/>
            <criterion comment="samba-swat is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91891"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91974"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91121"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91858"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91773"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21205" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1156: httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1156-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1156.html"/>
        <reference source="CESA" ref_id="CESA-2013:1156"/>
        <reference source="CVE" ref_id="CVE-2013-1896" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1896.html"/>
        <description>mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:20.764-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:17.627-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:33.300-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="mod_ssl is earlier than 1:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:91377"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:91527"/>
            <criterion comment="httpd is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:91204"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:91458"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:91572"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="mod_ssl is earlier than 1:2.2.15-29.el6.centos" test_ref="oval:org.mitre.oval:tst:91695"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-29.el6.centos" test_ref="oval:org.mitre.oval:tst:91753"/>
            <criterion comment="httpd is earlier than 0:2.2.15-29.el6.centos" test_ref="oval:org.mitre.oval:tst:92192"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-29.el6.centos" test_ref="oval:org.mitre.oval:tst:91949"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.15-29.el6.centos" test_ref="oval:org.mitre.oval:tst:92197"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="mod_ssl is earlier than 1:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:90720"/>
            <criterion comment="httpd is earlier than 0:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:90684"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:91517"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:91633"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="mod_ssl is earlier than 1:2.2.3-82.el5.centos" test_ref="oval:org.mitre.oval:tst:91566"/>
            <criterion comment="httpd is earlier than 0:2.2.3-82.el5.centos" test_ref="oval:org.mitre.oval:tst:92055"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-82.el5.centos" test_ref="oval:org.mitre.oval:tst:91598"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-82.el5.centos" test_ref="oval:org.mitre.oval:tst:91791"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21202" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0140: pango security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>pango</product>
          <product>evolution28-pango</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0140-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0140.html"/>
        <reference source="CESA" ref_id="CESA-2010:0140"/>
        <reference source="CVE" ref_id="CVE-2010-0421" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0421.html"/>
        <description>Array index error in the hb_ot_layout_build_glyph_classes function in pango/opentype/hb-ot-layout.cc in Pango before 1.27.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted font file, related to building a synthetic Glyph Definition (aka GDEF) table by using this font's charmap and the Unicode property database.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:20.857-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:37.819-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:57.349-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="pango-devel is earlier than 0:1.14.9-8.el5" test_ref="oval:org.mitre.oval:tst:98931"/>
          <criterion comment="pango is earlier than 0:1.14.9-8.el5" test_ref="oval:org.mitre.oval:tst:98974"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21201" version="187" class="patch">
      <metadata>
        <title>RHSA-2013:0825: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0825-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0825.html"/>
        <reference source="CVE" ref_id="CVE-2013-2728" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2728.html"/>
        <reference source="CVE" ref_id="CVE-2013-3324" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3324.html"/>
        <reference source="CVE" ref_id="CVE-2013-3325" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3325.html"/>
        <reference source="CVE" ref_id="CVE-2013-3326" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3326.html"/>
        <reference source="CVE" ref_id="CVE-2013-3327" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3327.html"/>
        <reference source="CVE" ref_id="CVE-2013-3328" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3328.html"/>
        <reference source="CVE" ref_id="CVE-2013-3329" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3329.html"/>
        <reference source="CVE" ref_id="CVE-2013-3330" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3330.html"/>
        <reference source="CVE" ref_id="CVE-2013-3331" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3331.html"/>
        <reference source="CVE" ref_id="CVE-2013-3332" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3332.html"/>
        <reference source="CVE" ref_id="CVE-2013-3333" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3333.html"/>
        <reference source="CVE" ref_id="CVE-2013-3334" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3334.html"/>
        <reference source="CVE" ref_id="CVE-2013-3335" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3335.html"/>
        <description>Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK &amp; Compiler before 3.7.0.1860 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2728, CVE-2013-3324, CVE-2013-3325, CVE-2013-3326, CVE-2013-3327, CVE-2013-3328, CVE-2013-3329, CVE-2013-3330, CVE-2013-3331, CVE-2013-3332, CVE-2013-3333, and CVE-2013-3334.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:56.853-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:17.008-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:32.701-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21201 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:11.451-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:48.717-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.285-1.el5" test_ref="oval:org.mitre.oval:tst:137786"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.285-1.el6" test_ref="oval:org.mitre.oval:tst:90762"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21200" version="81" class="patch">
      <metadata>
        <title>RHSA-2011:1212: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1212-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1212.html"/>
        <reference source="CESA" ref_id="CESA-2011:1212"/>
        <reference source="CVE" ref_id="CVE-2011-2482" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2482.html"/>
        <reference source="CVE" ref_id="CVE-2011-2491" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2491.html"/>
        <reference source="CVE" ref_id="CVE-2011-2495" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2495.html"/>
        <reference source="CVE" ref_id="CVE-2011-2517" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2517.html"/>
        <reference source="CVE" ref_id="CVE-2011-2519" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2519.html"/>
        <reference source="CVE" ref_id="CVE-2011-2901" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2901.html"/>
        <description>Off-by-one error in the __addr_ok macro in Xen 3.3 and earlier allows local 64 bit PV guest administrators to cause a denial of service (host crash) via unspecified hypercalls that ignore virtual-address bits.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:59.484-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:37.571-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:57.113-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:97450"/>
          <criterion comment="kernel is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:98361"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:97469"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:98248"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:98101"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:98245"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:98365"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:98405"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:98388"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:98118"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:97965"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:98398"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21198" version="367" class="patch">
      <metadata>
        <title>RHSA-2013:1505: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1505-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1505.html"/>
        <reference source="CESA" ref_id="CESA-2013:1505"/>
        <reference source="CVE" ref_id="CVE-2013-3829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3829.html"/>
        <reference source="CVE" ref_id="CVE-2013-4002" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4002.html"/>
        <reference source="CVE" ref_id="CVE-2013-5772" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5772.html"/>
        <reference source="CVE" ref_id="CVE-2013-5774" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5774.html"/>
        <reference source="CVE" ref_id="CVE-2013-5778" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5778.html"/>
        <reference source="CVE" ref_id="CVE-2013-5780" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5780.html"/>
        <reference source="CVE" ref_id="CVE-2013-5782" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5782.html"/>
        <reference source="CVE" ref_id="CVE-2013-5783" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5783.html"/>
        <reference source="CVE" ref_id="CVE-2013-5784" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5784.html"/>
        <reference source="CVE" ref_id="CVE-2013-5790" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5790.html"/>
        <reference source="CVE" ref_id="CVE-2013-5797" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5797.html"/>
        <reference source="CVE" ref_id="CVE-2013-5802" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5802.html"/>
        <reference source="CVE" ref_id="CVE-2013-5803" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5803.html"/>
        <reference source="CVE" ref_id="CVE-2013-5804" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5804.html"/>
        <reference source="CVE" ref_id="CVE-2013-5809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5809.html"/>
        <reference source="CVE" ref_id="CVE-2013-5814" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5814.html"/>
        <reference source="CVE" ref_id="CVE-2013-5817" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5817.html"/>
        <reference source="CVE" ref_id="CVE-2013-5820" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5820.html"/>
        <reference source="CVE" ref_id="CVE-2013-5823" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5823.html"/>
        <reference source="CVE" ref_id="CVE-2013-5825" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5825.html"/>
        <reference source="CVE" ref_id="CVE-2013-5829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5829.html"/>
        <reference source="CVE" ref_id="CVE-2013-5830" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5830.html"/>
        <reference source="CVE" ref_id="CVE-2013-5840" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5840.html"/>
        <reference source="CVE" ref_id="CVE-2013-5842" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5842.html"/>
        <reference source="CVE" ref_id="CVE-2013-5849" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5849.html"/>
        <reference source="CVE" ref_id="CVE-2013-5850" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5850.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:59.794-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:16.183-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:31.524-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:91677"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:91640"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:91221"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:91987"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:91812"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:91042"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:91138"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:91518"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:91705"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:91048"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21197" version="115" class="patch">
      <metadata>
        <title>RHSA-2013:1034: kernel security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1034-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1034.html"/>
        <reference source="CESA" ref_id="CESA-2013:1034"/>
        <reference source="CVE" ref_id="CVE-2012-6544" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6544.html"/>
        <reference source="CVE" ref_id="CVE-2012-6545" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6545.html"/>
        <reference source="CVE" ref_id="CVE-2013-0914" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0914.html"/>
        <reference source="CVE" ref_id="CVE-2013-1929" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1929.html"/>
        <reference source="CVE" ref_id="CVE-2013-3222" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3222.html"/>
        <reference source="CVE" ref_id="CVE-2013-3224" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3224.html"/>
        <reference source="CVE" ref_id="CVE-2013-3231" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3231.html"/>
        <reference source="CVE" ref_id="CVE-2013-3235" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3235.html"/>
        <description>net/tipc/socket.c in the Linux kernel before 3.9-rc7 does not initialize a certain data structure and a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:52.458-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:15.894-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:31.192-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:91434"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:90934"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:91482"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:91031"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:91014"/>
          <criterion comment="kernel is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:91486"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:91498"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:91495"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:91445"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:91282"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:91454"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:91497"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21196" version="383" class="patch">
      <metadata>
        <title>RHSA-2013:1081: java-1.5.0-ibm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1081-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1081.html"/>
        <reference source="CVE" ref_id="CVE-2013-1500" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1500.html"/>
        <reference source="CVE" ref_id="CVE-2013-1571" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1571.html"/>
        <reference source="CVE" ref_id="CVE-2013-2443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2443.html"/>
        <reference source="CVE" ref_id="CVE-2013-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2444.html"/>
        <reference source="CVE" ref_id="CVE-2013-2446" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2446.html"/>
        <reference source="CVE" ref_id="CVE-2013-2447" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2447.html"/>
        <reference source="CVE" ref_id="CVE-2013-2448" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2448.html"/>
        <reference source="CVE" ref_id="CVE-2013-2450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2450.html"/>
        <reference source="CVE" ref_id="CVE-2013-2452" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2452.html"/>
        <reference source="CVE" ref_id="CVE-2013-2454" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2454.html"/>
        <reference source="CVE" ref_id="CVE-2013-2455" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2455.html"/>
        <reference source="CVE" ref_id="CVE-2013-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2456.html"/>
        <reference source="CVE" ref_id="CVE-2013-2457" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2457.html"/>
        <reference source="CVE" ref_id="CVE-2013-2459" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2459.html"/>
        <reference source="CVE" ref_id="CVE-2013-2463" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2463.html"/>
        <reference source="CVE" ref_id="CVE-2013-2464" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2464.html"/>
        <reference source="CVE" ref_id="CVE-2013-2465" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2465.html"/>
        <reference source="CVE" ref_id="CVE-2013-2469" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2469.html"/>
        <reference source="CVE" ref_id="CVE-2013-2470" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2470.html"/>
        <reference source="CVE" ref_id="CVE-2013-2471" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2471.html"/>
        <reference source="CVE" ref_id="CVE-2013-2472" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2472.html"/>
        <reference source="CVE" ref_id="CVE-2013-2473" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2473.html"/>
        <reference source="CVE" ref_id="CVE-2013-3009" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3009.html"/>
        <reference source="CVE" ref_id="CVE-2013-3011" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3011.html"/>
        <reference source="CVE" ref_id="CVE-2013-3012" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3012.html"/>
        <reference source="CVE" ref_id="CVE-2013-3743" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3743.html"/>
        <reference source="CVE" ref_id="CVE-2013-4002" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4002.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 allows remote attackers to affect availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:59.642-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:15.197-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:30.304-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21196 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:09.838-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:45.901-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.3-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:136979"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.3-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137606"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.3-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137750"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.3-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137644"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.3-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137105"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.3-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137367"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.3-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137826"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.3-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137281"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91311"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91360"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90615"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91553"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91535"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91433"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90774"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21195" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0983: curl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>curl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0983-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0983.html"/>
        <reference source="CESA" ref_id="CESA-2013:0983"/>
        <reference source="CVE" ref_id="CVE-2013-2174" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2174.html"/>
        <description>Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string ending in a "%" (percent) character.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:03.074-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:15.083-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:30.187-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="curl is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:91403"/>
            <criterion comment="libcurl-devel is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:91169"/>
            <criterion comment="libcurl is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:91055"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="curl is earlier than 0:7.15.5-17.el5_9" test_ref="oval:org.mitre.oval:tst:91095"/>
            <criterion comment="curl-devel is earlier than 0:7.15.5-17.el5_9" test_ref="oval:org.mitre.oval:tst:91111"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21190" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1207: glibc security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1207-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1207.html"/>
        <reference source="CESA" ref_id="CESA-2012:1207"/>
        <reference source="CVE" ref_id="CVE-2012-3480" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3480.html"/>
        <description>Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Library (aka glibc or libc6) 2.16 allow local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:59.314-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:36.241-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:55.079-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="nscd is earlier than 0:2.5-81.el5_8.7" test_ref="oval:org.mitre.oval:tst:93962"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-81.el5_8.7" test_ref="oval:org.mitre.oval:tst:94342"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-81.el5_8.7" test_ref="oval:org.mitre.oval:tst:94240"/>
          <criterion comment="glibc-common is earlier than 0:2.5-81.el5_8.7" test_ref="oval:org.mitre.oval:tst:94252"/>
          <criterion comment="glibc is earlier than 0:2.5-81.el5_8.7" test_ref="oval:org.mitre.oval:tst:94226"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-81.el5_8.7" test_ref="oval:org.mitre.oval:tst:93958"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21189" version="55" class="patch">
      <metadata>
        <title>RHSA-2012:0323: httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0323-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0323.html"/>
        <reference source="CVE" ref_id="CVE-2011-3607" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3607.html"/>
        <reference source="CVE" ref_id="CVE-2011-3639" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3639.html"/>
        <reference source="CVE" ref_id="CVE-2012-0031" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0031.html"/>
        <reference source="CVE" ref_id="CVE-2012-0053" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0053.html"/>
        <description>protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:39.657-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:36.076-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:54.873-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="httpd-manual is earlier than 0:2.2.3-63.el5_8.1" test_ref="oval:org.mitre.oval:tst:92827"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.3-63.el5_8.1" test_ref="oval:org.mitre.oval:tst:92804"/>
          <criterion comment="httpd is earlier than 0:2.2.3-63.el5_8.1" test_ref="oval:org.mitre.oval:tst:92937"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.3-63.el5_8.1" test_ref="oval:org.mitre.oval:tst:92875"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21187" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0143: xulrunner security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0143-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0143.html"/>
        <reference source="CESA" ref_id="CESA-2012:0143"/>
        <reference source="CVE" ref_id="CVE-2011-3026" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3026.html"/>
        <description>Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:38.146-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:35.846-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:54.603-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-2.el6_2" test_ref="oval:org.mitre.oval:tst:92955"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-2.el6_2" test_ref="oval:org.mitre.oval:tst:92950"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-2.el6.centos" test_ref="oval:org.mitre.oval:tst:94918"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-2.el6.centos" test_ref="oval:org.mitre.oval:tst:95011"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-2.el5_7" test_ref="oval:org.mitre.oval:tst:93029"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-2.el5_7" test_ref="oval:org.mitre.oval:tst:92882"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21185" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0807: hypervkvpd security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>hypervkvpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0807-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0807.html"/>
        <reference source="CESA" ref_id="CESA-2013:0807"/>
        <reference source="CVE" ref_id="CVE-2012-5532" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5532.html"/>
        <description>The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.8-rc1, allows local users to cause a denial of service (daemon exit) via a crafted application that sends a Netlink message.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2669.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:27.473-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:14.869-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:29.905-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="hypervkvpd is earlier than 0:0-0.7.el5_9.3" test_ref="oval:org.mitre.oval:tst:91145"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21181" version="73" class="patch">
      <metadata>
        <title>RHSA-2013:0697: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0697-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0697.html"/>
        <reference source="CESA" ref_id="CESA-2013:0697"/>
        <reference source="CVE" ref_id="CVE-2013-0788" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0788.html"/>
        <reference source="CVE" ref_id="CVE-2013-0793" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0793.html"/>
        <reference source="CVE" ref_id="CVE-2013-0795" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0795.html"/>
        <reference source="CVE" ref_id="CVE-2013-0796" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0796.html"/>
        <reference source="CVE" ref_id="CVE-2013-0800" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0800.html"/>
        <description>Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to execute arbitrary code via crafted values that trigger attempted use of a (1) negative box boundary or (2) negative box size, leading to an out-of-bounds write operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:10.058-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:14.485-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:29.501-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:90367"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.5-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92270"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:17.0.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:90740"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:17.0.5-1.el5.centos" test_ref="oval:org.mitre.oval:tst:92017"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21180" version="409" class="patch">
      <metadata>
        <title>RHSA-2013:1447: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1447-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1447.html"/>
        <reference source="CESA" ref_id="CESA-2013:1447"/>
        <reference source="CVE" ref_id="CVE-2013-3829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3829.html"/>
        <reference source="CVE" ref_id="CVE-2013-4002" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4002.html"/>
        <reference source="CVE" ref_id="CVE-2013-5772" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5772.html"/>
        <reference source="CVE" ref_id="CVE-2013-5774" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5774.html"/>
        <reference source="CVE" ref_id="CVE-2013-5778" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5778.html"/>
        <reference source="CVE" ref_id="CVE-2013-5780" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5780.html"/>
        <reference source="CVE" ref_id="CVE-2013-5782" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5782.html"/>
        <reference source="CVE" ref_id="CVE-2013-5783" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5783.html"/>
        <reference source="CVE" ref_id="CVE-2013-5784" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5784.html"/>
        <reference source="CVE" ref_id="CVE-2013-5790" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5790.html"/>
        <reference source="CVE" ref_id="CVE-2013-5797" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5797.html"/>
        <reference source="CVE" ref_id="CVE-2013-5800" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5800.html"/>
        <reference source="CVE" ref_id="CVE-2013-5802" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5802.html"/>
        <reference source="CVE" ref_id="CVE-2013-5803" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5803.html"/>
        <reference source="CVE" ref_id="CVE-2013-5804" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5804.html"/>
        <reference source="CVE" ref_id="CVE-2013-5809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5809.html"/>
        <reference source="CVE" ref_id="CVE-2013-5814" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5814.html"/>
        <reference source="CVE" ref_id="CVE-2013-5817" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5817.html"/>
        <reference source="CVE" ref_id="CVE-2013-5820" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5820.html"/>
        <reference source="CVE" ref_id="CVE-2013-5823" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5823.html"/>
        <reference source="CVE" ref_id="CVE-2013-5825" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5825.html"/>
        <reference source="CVE" ref_id="CVE-2013-5829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5829.html"/>
        <reference source="CVE" ref_id="CVE-2013-5830" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5830.html"/>
        <reference source="CVE" ref_id="CVE-2013-5838" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5838.html"/>
        <reference source="CVE" ref_id="CVE-2013-5840" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5840.html"/>
        <reference source="CVE" ref_id="CVE-2013-5842" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5842.html"/>
        <reference source="CVE" ref_id="CVE-2013-5849" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5849.html"/>
        <reference source="CVE" ref_id="CVE-2013-5850" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5850.html"/>
        <reference source="CVE" ref_id="CVE-2013-5851" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5851.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via vectors related to JAXP.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:05.164-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:13.674-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:28.165-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.45-2.4.3.1.el5_10" test_ref="oval:org.mitre.oval:tst:91765"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.45-2.4.3.1.el5_10" test_ref="oval:org.mitre.oval:tst:91561"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.45-2.4.3.1.el5_10" test_ref="oval:org.mitre.oval:tst:90999"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.45-2.4.3.1.el5_10" test_ref="oval:org.mitre.oval:tst:91808"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.45-2.4.3.1.el5_10" test_ref="oval:org.mitre.oval:tst:91692"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21179" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0480: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0480-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0480.html"/>
        <reference source="CESA" ref_id="CESA-2012:0480"/>
        <reference source="CVE" ref_id="CVE-2012-1583" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1583.html"/>
        <description>Double free vulnerability in the xfrm6_tunnel_rcv function in net/ipv6/xfrm6_tunnel.c in the Linux kernel before 2.6.22, when the xfrm6_tunnel module is enabled, allows remote attackers to cause a denial of service (panic) via crafted IPv6 packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:45.888-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:35.732-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:54.392-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:93287"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:93298"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:92642"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:93359"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:92958"/>
          <criterion comment="kernel is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:93151"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:93302"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:93124"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:92479"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:93304"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:93237"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:93025"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21176" version="120" class="patch">
      <metadata>
        <title>RHSA-2012:0730: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0730-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0730.html"/>
        <reference source="CESA" ref_id="CESA-2012:0730"/>
        <reference source="CVE" ref_id="CVE-2012-1711" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1711.html"/>
        <reference source="CVE" ref_id="CVE-2012-1713" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1713.html"/>
        <reference source="CVE" ref_id="CVE-2012-1716" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1716.html"/>
        <reference source="CVE" ref_id="CVE-2012-1717" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1717.html"/>
        <reference source="CVE" ref_id="CVE-2012-1718" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1718.html"/>
        <reference source="CVE" ref_id="CVE-2012-1719" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1719.html"/>
        <reference source="CVE" ref_id="CVE-2012-1723" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1723.html"/>
        <reference source="CVE" ref_id="CVE-2012-1724" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1724.html"/>
        <reference source="CVE" ref_id="CVE-2012-1725" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1725.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, and 5 update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:56.778-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:35.408-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:53.952-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.27.1.10.8.el5_8" test_ref="oval:org.mitre.oval:tst:93782"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.27.1.10.8.el5_8" test_ref="oval:org.mitre.oval:tst:93613"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.27.1.10.8.el5_8" test_ref="oval:org.mitre.oval:tst:93763"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.27.1.10.8.el5_8" test_ref="oval:org.mitre.oval:tst:93868"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.27.1.10.8.el5_8" test_ref="oval:org.mitre.oval:tst:93816"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21171" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1090: ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1090-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1090.html"/>
        <reference source="CESA" ref_id="CESA-2013:1090"/>
        <reference source="CVE" ref_id="CVE-2013-4073" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4073.html"/>
        <description>The OpenSSL::SSL.verify_certificate_identity function in lib/openssl/ssl.rb in Ruby 1.8 before 1.8.7-p374, 1.9 before 1.9.3-p448, and 2.0 before 2.0.0-p247 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:14.387-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:12.043-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:25.912-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="ruby-rdoc is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:91540"/>
            <criterion comment="ruby-ri is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:90988"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:91554"/>
            <criterion comment="ruby-static is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:91608"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:91532"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:91265"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:91197"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:91298"/>
            <criterion comment="ruby is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:91472"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:91512"/>
            <criterion comment="ruby-ri is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:91538"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:91219"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:91547"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:91099"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:91125"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:91358"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:91606"/>
            <criterion comment="ruby is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:91418"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21167" version="115" class="patch">
      <metadata>
        <title>RHSA-2013:1476: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1476-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1476.html"/>
        <reference source="CESA" ref_id="CESA-2013:1476"/>
        <reference source="CVE" ref_id="CVE-2013-5590" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5590.html"/>
        <reference source="CVE" ref_id="CVE-2013-5595" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5595.html"/>
        <reference source="CVE" ref_id="CVE-2013-5597" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5597.html"/>
        <reference source="CVE" ref_id="CVE-2013-5599" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5599.html"/>
        <reference source="CVE" ref_id="CVE-2013-5600" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5600.html"/>
        <reference source="CVE" ref_id="CVE-2013-5601" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5601.html"/>
        <reference source="CVE" ref_id="CVE-2013-5602" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5602.html"/>
        <reference source="CVE" ref_id="CVE-2013-5604" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5604.html"/>
        <description>The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not properly initialize data, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via crafted documents.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:42.634-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:11.625-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:25.457-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:91643"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:91926"/>
            <criterion comment="firefox is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:91188"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner is earlier than 0:17.0.10-1.el6.centos" test_ref="oval:org.mitre.oval:tst:91614"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.10-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92245"/>
            <criterion comment="firefox is earlier than 0:17.0.10-1.el6.centos" test_ref="oval:org.mitre.oval:tst:91980"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:91448"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:91667"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:17.0.10-1.el5.centos" test_ref="oval:org.mitre.oval:tst:92269"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:91849"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21165" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0433: xorg-x11-server-utils security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>xorg-x11-server-utils</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0433-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0433.html"/>
        <reference source="CVE" ref_id="CVE-2011-0465" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0465.html"/>
        <reference source="CESA-2011:0433" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017321.html" ref_id="CESA-2011:0433-CentOS 5"/>
        <description>xrdb.c in xrdb before 1.0.9 in X.Org X11R7.6 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a (1) DHCP or (2) XDMCP message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:32.864-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:34.804-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:53.025-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21165 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:32.435-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:45.287-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="xorg-x11-server-utils is earlier than 0:7.1-5.el5_6.1" test_ref="oval:org.mitre.oval:tst:137349"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server-utils is earlier than 0:7.4-15.el6_0.1" test_ref="oval:org.mitre.oval:tst:97338"/>
            <criterion comment="xorg-x11-server-utils-debuginfo is earlier than 0:7.4-15.el6_0.1" test_ref="oval:org.mitre.oval:tst:137539"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21164" version="81" class="patch">
      <metadata>
        <title>RHSA-2012:0017: libxml2 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0017-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0017.html"/>
        <reference source="CESA" ref_id="CESA-2012:0017"/>
        <reference source="CVE" ref_id="CVE-2010-4008" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4008.html"/>
        <reference source="CVE" ref_id="CVE-2011-0216" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0216.html"/>
        <reference source="CVE" ref_id="CVE-2011-1944" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1944.html"/>
        <reference source="CVE" ref_id="CVE-2011-2834" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2834.html"/>
        <reference source="CVE" ref_id="CVE-2011-3905" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3905.html"/>
        <reference source="CVE" ref_id="CVE-2011-3919" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3919.html"/>
        <description>Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:33.265-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:34.563-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:52.732-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.12.el5_7.2" test_ref="oval:org.mitre.oval:tst:92691"/>
          <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.12.el5_7.2" test_ref="oval:org.mitre.oval:tst:92241"/>
          <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.12.el5_7.2" test_ref="oval:org.mitre.oval:tst:92444"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21163" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1474: qspice security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>qspice</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1474-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1474.html"/>
        <reference source="CESA" ref_id="CESA-2013:1474"/>
        <reference source="CVE" ref_id="CVE-2013-4282" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4282.html"/>
        <description>Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:23.738-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:11.540-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:25.356-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="qspice-libs-devel is earlier than 0:0.3.0-56.el5_10.1" test_ref="oval:org.mitre.oval:tst:91661"/>
          <criterion comment="qspice is earlier than 0:0.3.0-56.el5_10.1" test_ref="oval:org.mitre.oval:tst:91892"/>
          <criterion comment="qspice-libs is earlier than 0:0.3.0-56.el5_10.1" test_ref="oval:org.mitre.oval:tst:91767"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21162" version="6" class="patch">
      <metadata>
        <title>RHSA-2012:0688: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0688-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0688.html"/>
        <reference source="CVE" ref_id="CVE-2012-0779" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0779.html"/>
        <description>Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on Android 2.x and 3.x; and before 11.1.115.8 on Android 4.x allows remote attackers to execute arbitrary code via a crafted file, related to an "object confusion vulnerability," as exploited in the wild in May 2012.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:28.902-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:34.481-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:52.637-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21162 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:32.600-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:44.993-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.19-1.el5" test_ref="oval:org.mitre.oval:tst:137903"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.19-1.el6" test_ref="oval:org.mitre.oval:tst:93460"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21161" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1121: sos security update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>sos</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1121-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1121.html"/>
        <reference source="CESA" ref_id="CESA-2013:1121"/>
        <reference source="CVE" ref_id="CVE-2012-2664" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2664.html"/>
        <description>The sosreport utility in the Red Hat sos package before 2.2-29 does not remove the root user password information from the Kickstart configuration file (/root/anaconda-ks.cfg) when creating an archive of debugging information, which might allow attackers to obtain passwords or password hashes.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:45.625-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:11.451-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:25.258-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="sos is earlier than 0:1.7-9.62.el5_9.1" test_ref="oval:org.mitre.oval:tst:91473"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21158" version="6" class="patch">
      <metadata>
        <title>RHSA-2013:1813: php53 and php security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1813-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1813.html"/>
        <reference source="CESA" ref_id="CESA-2013:1813"/>
        <reference source="CVE" ref_id="CVE-2013-6420" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6420.html"/>
        <description>The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:23.515-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:11.254-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:24.722-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21158 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:39.681-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:28.749-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php53-intl is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91708"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91818"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91675"/>
            <criterion comment="php53 is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:92006"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91907"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91807"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91573"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91978"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91194"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91256"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91010"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91919"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91672"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91884"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91595"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91558"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91954"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91956"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91650"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91774"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91829"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php-common is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91380"/>
            <criterion comment="php-process is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91209"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91878"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91165"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91902"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91681"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91500"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91348"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91828"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91217"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91939"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91407"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91537"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91262"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91883"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91957"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91967"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91971"/>
            <criterion comment="php is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91688"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91840"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91772"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91950"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:92010"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91323"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91017"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91936"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91345"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21157" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0608: kvm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0608-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0608.html"/>
        <reference source="CESA" ref_id="CESA-2013:0608"/>
        <reference source="CVE" ref_id="CVE-2012-6075" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6075.html"/>
        <description>Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:53.131-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:11.147-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:24.532-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="kmod-kvm-debug is earlier than 0:83-262.el5_9.1" test_ref="oval:org.mitre.oval:tst:90742"/>
            <criterion comment="kmod-kvm is earlier than 0:83-262.el5_9.1" test_ref="oval:org.mitre.oval:tst:90883"/>
            <criterion comment="kvm-tools is earlier than 0:83-262.el5_9.1" test_ref="oval:org.mitre.oval:tst:90819"/>
            <criterion comment="kvm is earlier than 0:83-262.el5_9.1" test_ref="oval:org.mitre.oval:tst:90375"/>
            <criterion comment="kvm-qemu-img is earlier than 0:83-262.el5_9.1" test_ref="oval:org.mitre.oval:tst:90911"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="kmod-kvm-debug is earlier than 0:83-262.el5.centos.1" test_ref="oval:org.mitre.oval:tst:92101"/>
            <criterion comment="kmod-kvm is earlier than 0:83-262.el5.centos.1" test_ref="oval:org.mitre.oval:tst:92240"/>
            <criterion comment="kvm-tools is earlier than 0:83-262.el5.centos.1" test_ref="oval:org.mitre.oval:tst:92217"/>
            <criterion comment="kvm is earlier than 0:83-262.el5.centos.1" test_ref="oval:org.mitre.oval:tst:92170"/>
            <criterion comment="kvm-qemu-img is earlier than 0:83-262.el5.centos.1" test_ref="oval:org.mitre.oval:tst:92096"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21156" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0603: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0603-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0603.html"/>
        <reference source="CESA" ref_id="CESA-2013:0603"/>
        <reference source="CVE" ref_id="CVE-2013-0809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0809.html"/>
        <reference source="CVE" ref_id="CVE-2013-1493" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1493.html"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:34.622-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:11.038-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:24.350-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.8.0.el5_9" test_ref="oval:org.mitre.oval:tst:90757"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.8.0.el5_9" test_ref="oval:org.mitre.oval:tst:89961"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.8.0.el5_9" test_ref="oval:org.mitre.oval:tst:90389"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.8.0.el5_9" test_ref="oval:org.mitre.oval:tst:90850"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.8.0.el5_9" test_ref="oval:org.mitre.oval:tst:90673"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21155" version="107" class="patch">
      <metadata>
        <title>RHSA-2012:0007: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0007-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0007.html"/>
        <reference source="CESA" ref_id="CESA-2012:0007"/>
        <reference source="CVE" ref_id="CVE-2011-1020" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1020.html"/>
        <reference source="CVE" ref_id="CVE-2011-3637" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3637.html"/>
        <reference source="CVE" ref_id="CVE-2011-4077" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4077.html"/>
        <reference source="CVE" ref_id="CVE-2011-4132" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4132.html"/>
        <reference source="CVE" ref_id="CVE-2011-4324" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4324.html"/>
        <reference source="CVE" ref_id="CVE-2011-4325" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4325.html"/>
        <reference source="CVE" ref_id="CVE-2011-4330" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4330.html"/>
        <reference source="CVE" ref_id="CVE-2011-4348" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4348.html"/>
        <description>Race condition in the sctp_rcv function in net/sctp/input.c in the Linux kernel before 2.6.29 allows remote attackers to cause a denial of service (system hang) via SCTP packets.  NOTE: in some environments, this issue exists because of an incomplete fix for CVE-2011-2482.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:07.282-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:33.782-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:52.004-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:92460"/>
          <criterion comment="kernel is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:92424"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:92703"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:92679"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:92550"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:92777"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:92767"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:92663"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:92624"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:92188"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:92783"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:92660"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21151" version="649" class="patch">
      <metadata>
        <title>RHSA-2013:1507: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1507-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1507.html"/>
        <reference source="CVE" ref_id="CVE-2013-3829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3829.html"/>
        <reference source="CVE" ref_id="CVE-2013-4041" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4041.html"/>
        <reference source="CVE" ref_id="CVE-2013-5372" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5372.html"/>
        <reference source="CVE" ref_id="CVE-2013-5375" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5375.html"/>
        <reference source="CVE" ref_id="CVE-2013-5456" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5456.html"/>
        <reference source="CVE" ref_id="CVE-2013-5457" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5457.html"/>
        <reference source="CVE" ref_id="CVE-2013-5458" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5458.html"/>
        <reference source="CVE" ref_id="CVE-2013-5772" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5772.html"/>
        <reference source="CVE" ref_id="CVE-2013-5774" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5774.html"/>
        <reference source="CVE" ref_id="CVE-2013-5776" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5776.html"/>
        <reference source="CVE" ref_id="CVE-2013-5778" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5778.html"/>
        <reference source="CVE" ref_id="CVE-2013-5780" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5780.html"/>
        <reference source="CVE" ref_id="CVE-2013-5782" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5782.html"/>
        <reference source="CVE" ref_id="CVE-2013-5783" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5783.html"/>
        <reference source="CVE" ref_id="CVE-2013-5784" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5784.html"/>
        <reference source="CVE" ref_id="CVE-2013-5787" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5787.html"/>
        <reference source="CVE" ref_id="CVE-2013-5788" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5788.html"/>
        <reference source="CVE" ref_id="CVE-2013-5789" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5789.html"/>
        <reference source="CVE" ref_id="CVE-2013-5790" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5790.html"/>
        <reference source="CVE" ref_id="CVE-2013-5797" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5797.html"/>
        <reference source="CVE" ref_id="CVE-2013-5800" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5800.html"/>
        <reference source="CVE" ref_id="CVE-2013-5801" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5801.html"/>
        <reference source="CVE" ref_id="CVE-2013-5802" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5802.html"/>
        <reference source="CVE" ref_id="CVE-2013-5803" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5803.html"/>
        <reference source="CVE" ref_id="CVE-2013-5804" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5804.html"/>
        <reference source="CVE" ref_id="CVE-2013-5809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5809.html"/>
        <reference source="CVE" ref_id="CVE-2013-5812" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5812.html"/>
        <reference source="CVE" ref_id="CVE-2013-5814" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5814.html"/>
        <reference source="CVE" ref_id="CVE-2013-5817" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5817.html"/>
        <reference source="CVE" ref_id="CVE-2013-5818" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5818.html"/>
        <reference source="CVE" ref_id="CVE-2013-5819" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5819.html"/>
        <reference source="CVE" ref_id="CVE-2013-5820" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5820.html"/>
        <reference source="CVE" ref_id="CVE-2013-5823" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5823.html"/>
        <reference source="CVE" ref_id="CVE-2013-5824" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5824.html"/>
        <reference source="CVE" ref_id="CVE-2013-5825" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5825.html"/>
        <reference source="CVE" ref_id="CVE-2013-5829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5829.html"/>
        <reference source="CVE" ref_id="CVE-2013-5830" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5830.html"/>
        <reference source="CVE" ref_id="CVE-2013-5831" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5831.html"/>
        <reference source="CVE" ref_id="CVE-2013-5832" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5832.html"/>
        <reference source="CVE" ref_id="CVE-2013-5838" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5838.html"/>
        <reference source="CVE" ref_id="CVE-2013-5840" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5840.html"/>
        <reference source="CVE" ref_id="CVE-2013-5842" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5842.html"/>
        <reference source="CVE" ref_id="CVE-2013-5843" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5843.html"/>
        <reference source="CVE" ref_id="CVE-2013-5848" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5848.html"/>
        <reference source="CVE" ref_id="CVE-2013-5849" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5849.html"/>
        <reference source="CVE" ref_id="CVE-2013-5850" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5850.html"/>
        <reference source="CVE" ref_id="CVE-2013-5851" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5851.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via vectors related to JAXP.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:37.184-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:09.676-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:22.702-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21151 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:13.148-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:41.591-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.6.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137797"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.6.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137720"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.6.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137697"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.6.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137743"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.6.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137132"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.6.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137683"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.6.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91787"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.6.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91811"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.6.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91756"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.6.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91399"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.6.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91679"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.6.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91931"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21149" version="73" class="patch">
      <metadata>
        <title>RHSA-2013:0696: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0696-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0696.html"/>
        <reference source="CESA" ref_id="CESA-2013:0696"/>
        <reference source="CVE" ref_id="CVE-2013-0788" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0788.html"/>
        <reference source="CVE" ref_id="CVE-2013-0793" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0793.html"/>
        <reference source="CVE" ref_id="CVE-2013-0795" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0795.html"/>
        <reference source="CVE" ref_id="CVE-2013-0796" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0796.html"/>
        <reference source="CVE" ref_id="CVE-2013-0800" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0800.html"/>
        <description>Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to execute arbitrary code via crafted values that trigger attempted use of a (1) negative box boundary or (2) negative box size, leading to an out-of-bounds write operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:59:04.142-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:09.458-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:22.423-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:90804"/>
            <criterion comment="xulrunner is earlier than 0:17.0.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:91171"/>
            <criterion comment="firefox is earlier than 0:17.0.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:91004"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.5-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92148"/>
            <criterion comment="xulrunner is earlier than 0:17.0.5-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92273"/>
            <criterion comment="firefox is earlier than 0:17.0.5-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92059"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:90904"/>
            <criterion comment="xulrunner is earlier than 0:17.0.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:90848"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:17.0.5-1.el5.centos" test_ref="oval:org.mitre.oval:tst:92256"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:17.0.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:91043"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21148" version="73" class="patch">
      <metadata>
        <title>RHSA-2013:0272: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0272-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0272.html"/>
        <reference source="CESA" ref_id="CESA-2013:0272"/>
        <reference source="CVE" ref_id="CVE-2013-0775" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0775.html"/>
        <reference source="CVE" ref_id="CVE-2013-0776" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0776.html"/>
        <reference source="CVE" ref_id="CVE-2013-0780" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0780.html"/>
        <reference source="CVE" ref_id="CVE-2013-0782" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0782.html"/>
        <reference source="CVE" ref_id="CVE-2013-0783" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0783.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:31.039-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:09.280-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:22.150-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:89752"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.3-1.el6.centos" test_ref="oval:org.mitre.oval:tst:91960"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:90228"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-1.el5.centos" test_ref="oval:org.mitre.oval:tst:91894"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21146" version="101" class="patch">
      <metadata>
        <title>RHSA-2013:1166: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1166-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1166.html"/>
        <reference source="CESA" ref_id="CESA-2013:1166"/>
        <reference source="CVE" ref_id="CVE-2013-2147" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2147.html"/>
        <reference source="CVE" ref_id="CVE-2013-2164" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2164.html"/>
        <reference source="CVE" ref_id="CVE-2013-2206" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2206.html"/>
        <reference source="CVE" ref_id="CVE-2013-2224" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2224.html"/>
        <reference source="CVE" ref_id="CVE-2013-2232" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2232.html"/>
        <reference source="CVE" ref_id="CVE-2013-2234" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2234.html"/>
        <reference source="CVE" ref_id="CVE-2013-2237" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2237.html"/>
        <description>The key_notify_policy_flush function in net/key/af_key.c in the Linux kernel before 3.9 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify_policy interface of an IPSec key_socket.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:08.446-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:09.042-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:21.922-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:91499"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:91605"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:90923"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:91519"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:91094"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:91546"/>
          <criterion comment="kernel is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:91320"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:91619"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:91501"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:91649"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:91283"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:90986"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21145" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1236: xen security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1236-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1236.html"/>
        <reference source="CESA" ref_id="CESA-2012:1236"/>
        <reference source="CVE" ref_id="CVE-2012-3515" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3515.html"/>
        <description>Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:46.436-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:32.961-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:50.900-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="xen-libs is earlier than 0:3.0.3-135.el5_8.5" test_ref="oval:org.mitre.oval:tst:94255"/>
          <criterion comment="xen is earlier than 0:3.0.3-135.el5_8.5" test_ref="oval:org.mitre.oval:tst:94450"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-135.el5_8.5" test_ref="oval:org.mitre.oval:tst:94394"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21143" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0683: axis security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>axis</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0683-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0683.html"/>
        <reference source="CESA" ref_id="CESA-2013:0683"/>
        <reference source="CVE" ref_id="CVE-2012-5784" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5784.html"/>
        <description>Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:56.315-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:08.847-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:21.674-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="axis-javadoc is earlier than 0:1.2.1-2jpp.7.el5_9" test_ref="oval:org.mitre.oval:tst:90496"/>
          <criterion comment="axis-manual is earlier than 0:1.2.1-2jpp.7.el5_9" test_ref="oval:org.mitre.oval:tst:90950"/>
          <criterion comment="axis is earlier than 0:1.2.1-2jpp.7.el5_9" test_ref="oval:org.mitre.oval:tst:90930"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21141" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0942: krb5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0942-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0942.html"/>
        <reference source="CESA" ref_id="CESA-2013:0942"/>
        <reference source="CVE" ref_id="CVE-2002-2443" ref_url="https://www.redhat.com/security/data/cve/CVE-2002-2443.html"/>
        <description>schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged packet that triggers a communication loop, as demonstrated by krb_pingpong.nasl, a related issue to CVE-1999-0103.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:36.123-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:08.721-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:21.498-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="krb5-server-ldap is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:91146"/>
            <criterion comment="krb5-devel is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:90946"/>
            <criterion comment="krb5-workstation is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:91314"/>
            <criterion comment="krb5-libs is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:90910"/>
            <criterion comment="krb5-pkinit-openssl is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:90619"/>
            <criterion comment="krb5-server is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:91392"/>
            <criterion comment="krb5 is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:91170"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="krb5-server-ldap is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:91346"/>
            <criterion comment="krb5-devel is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:91029"/>
            <criterion comment="krb5-workstation is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:91368"/>
            <criterion comment="krb5-libs is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:90691"/>
            <criterion comment="krb5-server is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:91364"/>
            <criterion comment="krb5 is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:91177"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21140" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0580: cups security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0580-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0580.html"/>
        <reference source="CESA" ref_id="CESA-2013:0580"/>
        <reference source="CVE" ref_id="CVE-2012-5519" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5519.html"/>
        <description>CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:27.780-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:08.603-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:21.341-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="cups-php is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:90751"/>
            <criterion comment="cups-lpd is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:90668"/>
            <criterion comment="cups-devel is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:90645"/>
            <criterion comment="cups is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:90576"/>
            <criterion comment="cups-libs is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:89883"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="cups-devel is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:90213"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:90674"/>
            <criterion comment="cups is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:90732"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:90760"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21139" version="143" class="patch">
      <metadata>
        <title>RHSA-2013:0820: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0820-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0820.html"/>
        <reference source="CESA" ref_id="CESA-2013:0820"/>
        <reference source="CVE" ref_id="CVE-2013-0801" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0801.html"/>
        <reference source="CVE" ref_id="CVE-2013-1670" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1670.html"/>
        <reference source="CVE" ref_id="CVE-2013-1674" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1674.html"/>
        <reference source="CVE" ref_id="CVE-2013-1675" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1675.html"/>
        <reference source="CVE" ref_id="CVE-2013-1676" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1676.html"/>
        <reference source="CVE" ref_id="CVE-2013-1677" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1677.html"/>
        <reference source="CVE" ref_id="CVE-2013-1678" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1678.html"/>
        <reference source="CVE" ref_id="CVE-2013-1679" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1679.html"/>
        <reference source="CVE" ref_id="CVE-2013-1680" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1680.html"/>
        <reference source="CVE" ref_id="CVE-2013-1681" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1681.html"/>
        <description>Use-after-free vulnerability in the nsContentUtils::RemoveScriptBlocker function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:51.795-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:08.228-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:20.889-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:17.0.6-1.el6_4" test_ref="oval:org.mitre.oval:tst:90992"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.6-2.el6_4" test_ref="oval:org.mitre.oval:tst:91069"/>
            <criterion comment="xulrunner is earlier than 0:17.0.6-2.el6_4" test_ref="oval:org.mitre.oval:tst:91051"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:17.0.6-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92136"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.6-2.el6.centos" test_ref="oval:org.mitre.oval:tst:92243"/>
            <criterion comment="xulrunner is earlier than 0:17.0.6-2.el6.centos" test_ref="oval:org.mitre.oval:tst:92067"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.6-1.el5_9" test_ref="oval:org.mitre.oval:tst:91223"/>
            <criterion comment="xulrunner is earlier than 0:17.0.6-1.el5_9" test_ref="oval:org.mitre.oval:tst:90971"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:17.0.6-1.el5.centos" test_ref="oval:org.mitre.oval:tst:92150"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:17.0.6-1.el5_9" test_ref="oval:org.mitre.oval:tst:90967"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21138" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0197: postgresql security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0197-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0197.html"/>
        <reference source="CVE" ref_id="CVE-2010-4015" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4015.html"/>
        <reference source="CESA-2011:0197" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017381.html" ref_id="CESA-2011:0197-CentOS 5"/>
        <description>Buffer overflow in the gettoken function in contrib/intarray/_int_bool.c in the intarray array module in PostgreSQL 9.0.x before 9.0.3, 8.4.x before 8.4.7, 8.3.x before 8.3.14, and 8.2.x before 8.2.20 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via integers with a large number of digits to unspecified functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:24.319-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:32.783-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:50.677-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21138 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:26.252-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:41.060-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql-devel is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137871"/>
            <criterion comment="postgresql-pl is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137916"/>
            <criterion comment="postgresql-server is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137824"/>
            <criterion comment="postgresql-test is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137836"/>
            <criterion comment="postgresql is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137633"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137009"/>
            <criterion comment="postgresql-docs is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137807"/>
            <criterion comment="postgresql-libs is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137977"/>
            <criterion comment="postgresql-python is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137685"/>
            <criterion comment="postgresql-tcl is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137579"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97035"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:96874"/>
            <criterion comment="postgresql-debuginfo is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:137733"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97279"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97353"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97332"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97250"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97359"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:96952"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:96754"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:96635"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21136" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0870: tomcat5 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>tomcat5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0870-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0870.html"/>
        <reference source="CESA" ref_id="CESA-2013:0870"/>
        <reference source="CVE" ref_id="CVE-2013-1976" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1976.html"/>
        <description>The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0, and Red Hat Enterprise Linux 5 and 6, allow local users to change the ownership of arbitrary files via a symlink attack on (a) tomcat5-initd.log, (b) tomcat6-initd.log, (c) catalina.out, or (d) tomcat7-initd.log.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:59:06.291-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:08.122-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:20.730-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:90887"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:91158"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:91214"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:91085"/>
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:91109"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:90905"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:91078"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:90916"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:91300"/>
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:91065"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:90983"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21134" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1426: xorg-x11-server security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1426-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1426.html"/>
        <reference source="CESA" ref_id="CESA-2013:1426"/>
        <reference source="CVE" ref_id="CVE-2013-4396" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4396.html"/>
        <description>Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X.Org X11 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted ImageText request that triggers memory-allocation failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:55.983-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:07.713-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:20.278-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:90815"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:91616"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:91244"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:91310"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:91578"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:91636"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:91337"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:91709"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:91743"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-11.1.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92267"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-11.1.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92231"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-11.1.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92109"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-11.1.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92275"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-11.1.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92099"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-11.1.el6.centos.2" test_ref="oval:org.mitre.oval:tst:91981"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-11.1.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92172"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-11.1.el6.centos.2" test_ref="oval:org.mitre.oval:tst:91297"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.13.0-11.1.el6.centos.2" test_ref="oval:org.mitre.oval:tst:91710"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:91617"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:91845"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:91870"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:91038"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:91885"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:91663"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:91831"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:90902"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21133" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0321: cvs security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>cvs</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0321-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0321.html"/>
        <reference source="CESA" ref_id="CESA-2012:0321"/>
        <reference source="CVE" ref_id="CVE-2012-0804" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0804.html"/>
        <description>Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP response.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:47.980-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:32.579-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:50.454-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="cvs-inetd is earlier than 0:1.11.22-11.el5_8.1" test_ref="oval:org.mitre.oval:tst:92451"/>
            <criterion comment="cvs is earlier than 0:1.11.22-11.el5_8.1" test_ref="oval:org.mitre.oval:tst:92896"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="cvs is earlier than 0:1.11.23-11.el6_2.1" test_ref="oval:org.mitre.oval:tst:93081"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21131" version="607" class="patch">
      <metadata>
        <title>RHSA-2013:1060: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1060-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1060.html"/>
        <reference source="CVE" ref_id="CVE-2013-1500" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1500.html"/>
        <reference source="CVE" ref_id="CVE-2013-1571" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1571.html"/>
        <reference source="CVE" ref_id="CVE-2013-2400" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2400.html"/>
        <reference source="CVE" ref_id="CVE-2013-2407" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2407.html"/>
        <reference source="CVE" ref_id="CVE-2013-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2412.html"/>
        <reference source="CVE" ref_id="CVE-2013-2437" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2437.html"/>
        <reference source="CVE" ref_id="CVE-2013-2442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2442.html"/>
        <reference source="CVE" ref_id="CVE-2013-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2444.html"/>
        <reference source="CVE" ref_id="CVE-2013-2446" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2446.html"/>
        <reference source="CVE" ref_id="CVE-2013-2447" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2447.html"/>
        <reference source="CVE" ref_id="CVE-2013-2448" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2448.html"/>
        <reference source="CVE" ref_id="CVE-2013-2449" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2449.html"/>
        <reference source="CVE" ref_id="CVE-2013-2450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2450.html"/>
        <reference source="CVE" ref_id="CVE-2013-2451" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2451.html"/>
        <reference source="CVE" ref_id="CVE-2013-2452" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2452.html"/>
        <reference source="CVE" ref_id="CVE-2013-2453" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2453.html"/>
        <reference source="CVE" ref_id="CVE-2013-2454" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2454.html"/>
        <reference source="CVE" ref_id="CVE-2013-2455" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2455.html"/>
        <reference source="CVE" ref_id="CVE-2013-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2456.html"/>
        <reference source="CVE" ref_id="CVE-2013-2457" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2457.html"/>
        <reference source="CVE" ref_id="CVE-2013-2458" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2458.html"/>
        <reference source="CVE" ref_id="CVE-2013-2459" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2459.html"/>
        <reference source="CVE" ref_id="CVE-2013-2460" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2460.html"/>
        <reference source="CVE" ref_id="CVE-2013-2462" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2462.html"/>
        <reference source="CVE" ref_id="CVE-2013-2463" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2463.html"/>
        <reference source="CVE" ref_id="CVE-2013-2464" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2464.html"/>
        <reference source="CVE" ref_id="CVE-2013-2465" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2465.html"/>
        <reference source="CVE" ref_id="CVE-2013-2466" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2466.html"/>
        <reference source="CVE" ref_id="CVE-2013-2468" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2468.html"/>
        <reference source="CVE" ref_id="CVE-2013-2469" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2469.html"/>
        <reference source="CVE" ref_id="CVE-2013-2470" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2470.html"/>
        <reference source="CVE" ref_id="CVE-2013-2471" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2471.html"/>
        <reference source="CVE" ref_id="CVE-2013-2472" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2472.html"/>
        <reference source="CVE" ref_id="CVE-2013-2473" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2473.html"/>
        <reference source="CVE" ref_id="CVE-2013-3006" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3006.html"/>
        <reference source="CVE" ref_id="CVE-2013-3007" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3007.html"/>
        <reference source="CVE" ref_id="CVE-2013-3008" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3008.html"/>
        <reference source="CVE" ref_id="CVE-2013-3009" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3009.html"/>
        <reference source="CVE" ref_id="CVE-2013-3010" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3010.html"/>
        <reference source="CVE" ref_id="CVE-2013-3011" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3011.html"/>
        <reference source="CVE" ref_id="CVE-2013-3012" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3012.html"/>
        <reference source="CVE" ref_id="CVE-2013-3744" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3744.html"/>
        <reference source="CVE" ref_id="CVE-2013-4002" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4002.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 allows remote attackers to affect availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:45.264-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:06.404-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:18.492-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21131 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:10.782-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:37.334-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.5.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137681"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.5.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137771"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.5.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137789"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.5.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137793"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.5.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137198"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.5.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137716"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.5.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:91108"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.5.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:91526"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.5.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:91054"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.5.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:91341"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.5.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:91331"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.5.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:91387"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21130" version="5" class="patch">
      <metadata>
        <title>RHSA-2012:0376: systemtap security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>systemtap</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0376-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0376.html"/>
        <reference source="CESA" ref_id="CESA-2012:0376"/>
        <reference source="CVE" ref_id="CVE-2012-0875" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0875.html"/>
        <description>SystemTap 1.7, 1.6.7, and probably other versions, when unprivileged mode is enabled, allows local users to obtain sensitive information from kernel memory or cause a denial of service (kernel panic and crash) via vectors related to crafted DWARF data, which triggers a read of an invalid pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:21.128-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:32.451-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:50.299-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="systemtap-runtime is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:92899"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:92917"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:92945"/>
            <criterion comment="systemtap is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:92914"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:92634"/>
            <criterion comment="systemtap-server is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:92523"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="systemtap-runtime is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:92849"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:92855"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:92134"/>
            <criterion comment="systemtap is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:92853"/>
            <criterion comment="systemtap-grapher is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:92615"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:93008"/>
            <criterion comment="systemtap-server is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:92097"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21129" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1804: libjpeg security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>libjpeg</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1804-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1804.html"/>
        <reference source="CESA" ref_id="CESA-2013:1804"/>
        <reference source="CVE" ref_id="CVE-2013-6629" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6629.html"/>
        <description>The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:55.563-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:06.301-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:18.371-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libjpeg-devel is earlier than 0:6b-38" test_ref="oval:org.mitre.oval:tst:91191"/>
          <criterion comment="libjpeg is earlier than 0:6b-38" test_ref="oval:org.mitre.oval:tst:91802"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21127" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0250: elinks security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>elinks</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0250-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0250.html"/>
        <reference source="CESA" ref_id="CESA-2013:0250"/>
        <reference source="CVE" ref_id="CVE-2012-4545" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4545.html"/>
        <description>The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates user credentials through GSSAPI, which allows remote servers to authenticate as the client via the delegated credentials.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:51.639-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:06.185-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:18.251-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criterion comment="elinks is earlier than 0:0.12-0.21.pre5.el6_3" test_ref="oval:org.mitre.oval:tst:90393"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="elinks is earlier than 0:0.11.1-8.el5_9" test_ref="oval:org.mitre.oval:tst:90270"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21124" version="73" class="patch">
      <metadata>
        <title>RHSA-2013:0271: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>devhelp</product>
          <product>firefox</product>
          <product>xulrunner</product>
          <product>yelp</product>
          <product>libproxy</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0271-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0271.html"/>
        <reference source="CESA" ref_id="CESA-2013:0271"/>
        <reference source="CVE" ref_id="CVE-2013-0775" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0775.html"/>
        <reference source="CVE" ref_id="CVE-2013-0776" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0776.html"/>
        <reference source="CVE" ref_id="CVE-2013-0780" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0780.html"/>
        <reference source="CVE" ref_id="CVE-2013-0782" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0782.html"/>
        <reference source="CVE" ref_id="CVE-2013-0783" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0783.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:40.486-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:05.830-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:17.772-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 and Centos 6 section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="yelp is earlier than 0:2.28.1-17.el6_3" test_ref="oval:org.mitre.oval:tst:90204"/>
            <criterion comment="libproxy-bin is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:90392"/>
            <criterion comment="libproxy-mozjs is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:89980"/>
            <criterion comment="libproxy-devel is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:90290"/>
            <criterion comment="libproxy-webkit is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:90084"/>
            <criterion comment="libproxy is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:89815"/>
            <criterion comment="libproxy-gnome is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:90044"/>
            <criterion comment="libproxy-python is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:90487"/>
            <criterion comment="libproxy-kde is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:90223"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92116"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-1.el6.centos" test_ref="oval:org.mitre.oval:tst:91241"/>
            <criterion comment="firefox is earlier than 0:17.0.3-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92094"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:90337"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:90458"/>
            <criterion comment="firefox is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:90216"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="yelp is earlier than 0:2.16.0-30.el5_9" test_ref="oval:org.mitre.oval:tst:90300"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-23.el5_9" test_ref="oval:org.mitre.oval:tst:90387"/>
            <criterion comment="devhelp is earlier than 0:0.12-23.el5_9" test_ref="oval:org.mitre.oval:tst:90258"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:90424"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:90491"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:17.0.3-1.el5.centos" test_ref="oval:org.mitre.oval:tst:92139"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:90231"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21123" version="81" class="patch">
      <metadata>
        <title>RHSA-2011:0474: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0474-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0474.html"/>
        <reference source="CESA" ref_id="CESA-2011:0474"/>
        <reference source="CVE" ref_id="CVE-2011-0073" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0073.html"/>
        <reference source="CVE" ref_id="CVE-2011-0074" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0074.html"/>
        <reference source="CVE" ref_id="CVE-2011-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0075.html"/>
        <reference source="CVE" ref_id="CVE-2011-0077" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0077.html"/>
        <reference source="CVE" ref_id="CVE-2011-0078" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0078.html"/>
        <reference source="CVE" ref_id="CVE-2011-0080" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0080.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:33.244-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:31.992-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:49.701-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-17.el5_6" test_ref="oval:org.mitre.oval:tst:97801"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21119" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0827: openswan security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>openswan</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0827-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0827.html"/>
        <reference source="CESA" ref_id="CESA-2013:0827"/>
        <reference source="CVE" ref_id="CVE-2013-2053" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2053.html"/>
        <description>Buffer overflow in the atodn function in Openswan before 2.6.39, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records.  NOTE: this might be the same vulnerability as CVE-2013-2052 and CVE-2013-2054.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:28.060-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:05.593-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:17.489-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openswan is earlier than 0:2.6.32-20.el6_4" test_ref="oval:org.mitre.oval:tst:91137"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-20.el6_4" test_ref="oval:org.mitre.oval:tst:90925"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openswan is earlier than 0:2.6.32-5.el5_9" test_ref="oval:org.mitre.oval:tst:90802"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-5.el5_9" test_ref="oval:org.mitre.oval:tst:90844"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21116" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:0646: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0646-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0646.html"/>
        <reference source="CESA" ref_id="CESA-2013:0646"/>
        <reference source="CVE" ref_id="CVE-2013-0272" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0272.html"/>
        <reference source="CVE" ref_id="CVE-2013-0273" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0273.html"/>
        <reference source="CVE" ref_id="CVE-2013-0274" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0274.html"/>
        <description>upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging access to the local network.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:28.816-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:05.346-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:17.156-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="pidgin-perl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90912"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90937"/>
            <criterion comment="pidgin-docs is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90641"/>
            <criterion comment="libpurple is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90825"/>
            <criterion comment="libpurple-perl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90779"/>
            <criterion comment="finch-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:91023"/>
            <criterion comment="finch is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90964"/>
            <criterion comment="libpurple-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:91024"/>
            <criterion comment="pidgin-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90702"/>
            <criterion comment="pidgin is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90976"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:90965"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:90432"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:90855"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:90234"/>
            <criterion comment="finch-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:91050"/>
            <criterion comment="finch is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:90540"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:90942"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:90127"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:90646"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21115" version="5" class="patch">
      <metadata>
        <title>RHSA-2012:0310: nfs-utils security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>nfs-utils</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0310-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0310.html"/>
        <reference source="CVE" ref_id="CVE-2011-1749" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1749.html"/>
        <description>The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to corrupt this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:32.847-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:31.645-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:49.401-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="nfs-utils is earlier than 1:1.0.9-60.el5" test_ref="oval:org.mitre.oval:tst:92738"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21114" version="87" class="patch">
      <metadata>
        <title>RHSA-2013:1307: php53 security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>php53</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1307-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1307.html"/>
        <reference source="CESA" ref_id="CESA-2013:1307"/>
        <reference source="CVE" ref_id="CVE-2006-7243" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7243.html"/>
        <reference source="CVE" ref_id="CVE-2011-1398" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1398.html"/>
        <reference source="CVE" ref_id="CVE-2012-0831" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0831.html"/>
        <reference source="CVE" ref_id="CVE-2012-2688" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2688.html"/>
        <reference source="CVE" ref_id="CVE-2013-1643" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1643.html"/>
        <reference source="CVE" ref_id="CVE-2013-4248" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4248.html"/>
        <description>The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:25.586-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:05.115-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:16.959-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="php53-odbc is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91736"/>
          <criterion comment="php53-mbstring is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91294"/>
          <criterion comment="php53-gd is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91225"/>
          <criterion comment="php53-intl is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91436"/>
          <criterion comment="php53-pgsql is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91712"/>
          <criterion comment="php53-mysql is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91511"/>
          <criterion comment="php53-dba is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91536"/>
          <criterion comment="php53-process is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91735"/>
          <criterion comment="php53 is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91671"/>
          <criterion comment="php53-common is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91764"/>
          <criterion comment="php53-imap is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91732"/>
          <criterion comment="php53-bcmath is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91296"/>
          <criterion comment="php53-ldap is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91747"/>
          <criterion comment="php53-soap is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91701"/>
          <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91275"/>
          <criterion comment="php53-cli is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91733"/>
          <criterion comment="php53-devel is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91484"/>
          <criterion comment="php53-pspell is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91639"/>
          <criterion comment="php53-xml is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91738"/>
          <criterion comment="php53-snmp is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91585"/>
          <criterion comment="php53-pdo is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:91557"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21111" version="327" class="patch">
      <metadata>
        <title>RHSA-2013:0823: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0823-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0823.html"/>
        <reference source="CVE" ref_id="CVE-2013-0170" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0170.html"/>
        <reference source="CVE" ref_id="CVE-2013-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0401.html"/>
        <reference source="CVE" ref_id="CVE-2013-1491" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1491.html"/>
        <reference source="CVE" ref_id="CVE-2013-1537" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1537.html"/>
        <reference source="CVE" ref_id="CVE-2013-1540" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1540.html"/>
        <reference source="CVE" ref_id="CVE-2013-1557" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1557.html"/>
        <reference source="CVE" ref_id="CVE-2013-1563" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1563.html"/>
        <reference source="CVE" ref_id="CVE-2013-1569" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1569.html"/>
        <reference source="CVE" ref_id="CVE-2013-2383" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2383.html"/>
        <reference source="CVE" ref_id="CVE-2013-2384" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2384.html"/>
        <reference source="CVE" ref_id="CVE-2013-2394" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2394.html"/>
        <reference source="CVE" ref_id="CVE-2013-2417" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2417.html"/>
        <reference source="CVE" ref_id="CVE-2013-2418" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2418.html"/>
        <reference source="CVE" ref_id="CVE-2013-2419" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2419.html"/>
        <reference source="CVE" ref_id="CVE-2013-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2420.html"/>
        <reference source="CVE" ref_id="CVE-2013-2422" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2422.html"/>
        <reference source="CVE" ref_id="CVE-2013-2424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2424.html"/>
        <reference source="CVE" ref_id="CVE-2013-2429" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2429.html"/>
        <reference source="CVE" ref_id="CVE-2013-2430" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2430.html"/>
        <reference source="CVE" ref_id="CVE-2013-2432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2432.html"/>
        <reference source="CVE" ref_id="CVE-2013-2433" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2433.html"/>
        <reference source="CVE" ref_id="CVE-2013-2435" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2435.html"/>
        <reference source="CVE" ref_id="CVE-2013-2440" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2440.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2435.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:48.191-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:04.357-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:15.988-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21111 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:26.566-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:35.295-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.13.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137176"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.13.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137693"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.13.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137603"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.13.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137719"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.13.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137800"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.13.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137825"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.13.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:136852"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.13.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137840"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90595"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91248"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90963"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90780"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90933"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91239"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91053"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21109" version="313" class="patch">
      <metadata>
        <title>RHSA-2013:0624: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0624-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0624.html"/>
        <reference source="CVE" ref_id="CVE-2012-5085" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5085.html"/>
        <reference source="CVE" ref_id="CVE-2013-0409" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0409.html"/>
        <reference source="CVE" ref_id="CVE-2013-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0424.html"/>
        <reference source="CVE" ref_id="CVE-2013-0425" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0425.html"/>
        <reference source="CVE" ref_id="CVE-2013-0426" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0426.html"/>
        <reference source="CVE" ref_id="CVE-2013-0427" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0427.html"/>
        <reference source="CVE" ref_id="CVE-2013-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0428.html"/>
        <reference source="CVE" ref_id="CVE-2013-0432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0432.html"/>
        <reference source="CVE" ref_id="CVE-2013-0433" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0433.html"/>
        <reference source="CVE" ref_id="CVE-2013-0434" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0434.html"/>
        <reference source="CVE" ref_id="CVE-2013-0440" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0440.html"/>
        <reference source="CVE" ref_id="CVE-2013-0442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0442.html"/>
        <reference source="CVE" ref_id="CVE-2013-0443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0443.html"/>
        <reference source="CVE" ref_id="CVE-2013-0445" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0445.html"/>
        <reference source="CVE" ref_id="CVE-2013-0450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0450.html"/>
        <reference source="CVE" ref_id="CVE-2013-0809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0809.html"/>
        <reference source="CVE" ref_id="CVE-2013-1476" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1476.html"/>
        <reference source="CVE" ref_id="CVE-2013-1478" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1478.html"/>
        <reference source="CVE" ref_id="CVE-2013-1480" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1480.html"/>
        <reference source="CVE" ref_id="CVE-2013-1481" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1481.html"/>
        <reference source="CVE" ref_id="CVE-2013-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1486.html"/>
        <reference source="CVE" ref_id="CVE-2013-1493" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1493.html"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:30.258-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:03.567-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:15.278-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21109 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:16.802-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:33.539-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137847"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137250"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137808"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137819"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137703"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137755"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137212"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137552"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90818"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90926"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90561"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90647"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90874"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90931"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21106" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1266: bind97 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1266-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1266.html"/>
        <reference source="CESA" ref_id="CESA-2012:1266"/>
        <reference source="CVE" ref_id="CVE-2012-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4244.html"/>
        <description>ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a long resource record.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:52.260-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:31.224-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:48.951-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="bind97-libs is earlier than 32:9.7.0-10.P2.el5_8.3" test_ref="oval:org.mitre.oval:tst:94254"/>
          <criterion comment="bind97-chroot is earlier than 32:9.7.0-10.P2.el5_8.3" test_ref="oval:org.mitre.oval:tst:94576"/>
          <criterion comment="bind97 is earlier than 32:9.7.0-10.P2.el5_8.3" test_ref="oval:org.mitre.oval:tst:94484"/>
          <criterion comment="bind97-utils is earlier than 32:9.7.0-10.P2.el5_8.3" test_ref="oval:org.mitre.oval:tst:93688"/>
          <criterion comment="bind97-devel is earlier than 32:9.7.0-10.P2.el5_8.3" test_ref="oval:org.mitre.oval:tst:94493"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21105" version="81" class="patch">
      <metadata>
        <title>RHSA-2011:0429: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0429-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0429.html"/>
        <reference source="CESA" ref_id="CESA-2011:0429"/>
        <reference source="CVE" ref_id="CVE-2010-4346" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4346.html"/>
        <reference source="CVE" ref_id="CVE-2011-0521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0521.html"/>
        <reference source="CVE" ref_id="CVE-2011-0710" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0710.html"/>
        <reference source="CVE" ref_id="CVE-2011-1010" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1010.html"/>
        <reference source="CVE" ref_id="CVE-2011-1090" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1090.html"/>
        <reference source="CVE" ref_id="CVE-2011-1478" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1478.html"/>
        <description>The napi_reuse_skb function in net/core/dev.c in the Generic Receive Offload (GRO) implementation in the Linux kernel before 2.6.38 does not reset the values of certain structure members, which might allow remote attackers to cause a denial of service (NULL pointer dereference) via a malformed VLAN frame.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:25.591-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:30.931-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:48.650-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:97826"/>
          <criterion comment="kernel is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:97454"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:97553"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:97401"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:97615"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:97347"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:97650"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:97765"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:97854"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:97676"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:97736"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:97821"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21104" version="73" class="patch">
      <metadata>
        <title>RHSA-2013:1791: nss and nspr security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>nspr</product>
          <product>nss</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1791-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1791.html"/>
        <reference source="CESA" ref_id="CESA-2013:1791"/>
        <reference source="CVE" ref_id="CVE-2013-1739" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1739.html"/>
        <reference source="CVE" ref_id="CVE-2013-1741" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1741.html"/>
        <reference source="CVE" ref_id="CVE-2013-5605" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5605.html"/>
        <reference source="CVE" ref_id="CVE-2013-5606" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5606.html"/>
        <reference source="CVE" ref_id="CVE-2013-5607" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5607.html"/>
        <description>Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:56.177-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:03.369-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:15.103-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="nspr-devel is earlier than 0:4.10.2-2.el5_10" test_ref="oval:org.mitre.oval:tst:91836"/>
          <criterion comment="nspr is earlier than 0:4.10.2-2.el5_10" test_ref="oval:org.mitre.oval:tst:91456"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-3.el5_10" test_ref="oval:org.mitre.oval:tst:91487"/>
          <criterion comment="nss-tools is earlier than 0:3.15.3-3.el5_10" test_ref="oval:org.mitre.oval:tst:91593"/>
          <criterion comment="nss-devel is earlier than 0:3.15.3-3.el5_10" test_ref="oval:org.mitre.oval:tst:91768"/>
          <criterion comment="nss is earlier than 0:3.15.3-3.el5_10" test_ref="oval:org.mitre.oval:tst:91683"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21097" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0599: xen security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0599-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0599.html"/>
        <reference source="CESA" ref_id="CESA-2013:0599"/>
        <reference source="CVE" ref_id="CVE-2012-6075" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6075.html"/>
        <description>Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:40.601-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:02.972-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:14.452-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="xen-libs is earlier than 0:3.0.3-142.el5_9.2" test_ref="oval:org.mitre.oval:tst:90811"/>
          <criterion comment="xen is earlier than 0:3.0.3-142.el5_9.2" test_ref="oval:org.mitre.oval:tst:90672"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-142.el5_9.2" test_ref="oval:org.mitre.oval:tst:90733"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21094" version="61" class="patch">
      <metadata>
        <title>RHSA-2013:1814: php security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1814-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1814.html"/>
        <reference source="CESA" ref_id="CESA-2013:1814"/>
        <reference source="CVE" ref_id="CVE-2011-1398" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1398.html"/>
        <reference source="CVE" ref_id="CVE-2012-2688" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2688.html"/>
        <reference source="CVE" ref_id="CVE-2013-1643" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1643.html"/>
        <reference source="CVE" ref_id="CVE-2013-6420" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6420.html"/>
        <description>The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:33.250-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:02.771-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:14.240-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21094 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:41.298-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:23.854-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="php-common is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:91964"/>
          <criterion comment="php-odbc is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:91762"/>
          <criterion comment="php-snmp is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:91914"/>
          <criterion comment="php-mysql is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:92003"/>
          <criterion comment="php-dba is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:91800"/>
          <criterion comment="php-devel is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:91707"/>
          <criterion comment="php-gd is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:91969"/>
          <criterion comment="php-bcmath is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:91022"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:91961"/>
          <criterion comment="php-ncurses is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:91272"/>
          <criterion comment="php-pgsql is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:92014"/>
          <criterion comment="php-cli is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:91565"/>
          <criterion comment="php is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:91977"/>
          <criterion comment="php-imap is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:91819"/>
          <criterion comment="php-pdo is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:92013"/>
          <criterion comment="php-mbstring is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:91893"/>
          <criterion comment="php-xml is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:91955"/>
          <criterion comment="php-ldap is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:91714"/>
          <criterion comment="php-soap is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:91890"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21092" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:1475: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1475-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1475.html"/>
        <reference source="CESA" ref_id="CESA-2013:1475"/>
        <reference source="CVE" ref_id="CVE-2013-0255" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0255.html"/>
        <reference source="CVE" ref_id="CVE-2013-1000" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1000.html"/>
        <description>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:07.659-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:02.541-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:14.019-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql-devel is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:91210"/>
            <criterion comment="postgresql is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:91903"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:91694"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:90932"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:91788"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:91252"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:91881"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:91810"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:91746"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:91861"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91711"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91494"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91685"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91420"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91447"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91748"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91925"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91362"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91655"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91623"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91744"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91528"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21090" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1790: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1790-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1790.html"/>
        <reference source="CESA" ref_id="CESA-2013:1790"/>
        <reference source="CVE" ref_id="CVE-2013-4355" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4355.html"/>
        <description>Xen 4.3.x and earlier does not properly handle certain errors, which allows local HVM guests to obtain hypervisor stack memory via a (1) port or (2) memory mapped I/O write or (3) other unspecified operations related to addresses without associated memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:29.003-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:02.401-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:13.898-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:91686"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:91587"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:91586"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:91460"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:91856"/>
          <criterion comment="kernel is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:91801"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:91437"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:91635"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:91521"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:91187"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:91690"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:91319"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21089" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0306: krb5 security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0306-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0306.html"/>
        <reference source="CVE" ref_id="CVE-2011-1526" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1526.html"/>
        <description>ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, overwrite, delete, or read files, via standard FTP commands, related to missing autoconf tests in a configure script.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:46.058-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:30.082-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:47.610-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="krb5-libs is earlier than 0:1.6.1-70.el5" test_ref="oval:org.mitre.oval:tst:93047"/>
          <criterion comment="krb5-server is earlier than 0:1.6.1-70.el5" test_ref="oval:org.mitre.oval:tst:92742"/>
          <criterion comment="krb5 is earlier than 0:1.6.1-70.el5" test_ref="oval:org.mitre.oval:tst:92079"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.6.1-70.el5" test_ref="oval:org.mitre.oval:tst:92574"/>
          <criterion comment="krb5-workstation is earlier than 0:1.6.1-70.el5" test_ref="oval:org.mitre.oval:tst:93027"/>
          <criterion comment="krb5-devel is earlier than 0:1.6.1-70.el5" test_ref="oval:org.mitre.oval:tst:93055"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21087" version="133" class="patch">
      <metadata>
        <title>RHSA-2012:0387: firefox security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0387-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0387.html"/>
        <reference source="CESA" ref_id="CESA-2012:0387"/>
        <reference source="CVE" ref_id="CVE-2012-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0451.html"/>
        <reference source="CVE" ref_id="CVE-2012-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0455.html"/>
        <reference source="CVE" ref_id="CVE-2012-0456" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0456.html"/>
        <reference source="CVE" ref_id="CVE-2012-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0457.html"/>
        <reference source="CVE" ref_id="CVE-2012-0458" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0458.html"/>
        <reference source="CVE" ref_id="CVE-2012-0459" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0459.html"/>
        <reference source="CVE" ref_id="CVE-2012-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0460.html"/>
        <reference source="CVE" ref_id="CVE-2012-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0461.html"/>
        <reference source="CVE" ref_id="CVE-2012-0462" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0462.html"/>
        <reference source="CVE" ref_id="CVE-2012-0464" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0464.html"/>
        <description>Use-after-free vulnerability in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to execute arbitrary code via vectors involving an empty argument to the array.join function in conjunction with the triggering of garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:26.579-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:29.487-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:47.024-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.3-1.el5_8" test_ref="oval:org.mitre.oval:tst:93064"/>
            <criterion comment="xulrunner is earlier than 0:10.0.3-1.el5_8" test_ref="oval:org.mitre.oval:tst:92951"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:10.0.3-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94850"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:10.0.3-1.el5_8" test_ref="oval:org.mitre.oval:tst:93068"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.3-1.el6_2" test_ref="oval:org.mitre.oval:tst:92147"/>
            <criterion comment="xulrunner is earlier than 0:10.0.3-1.el6_2" test_ref="oval:org.mitre.oval:tst:92353"/>
            <criterion comment="firefox is earlier than 0:10.0.3-1.el6_2" test_ref="oval:org.mitre.oval:tst:93085"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.3-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94340"/>
            <criterion comment="xulrunner is earlier than 0:10.0.3-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94760"/>
            <criterion comment="firefox is earlier than 0:10.0.3-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94988"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21084" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:1135: nss and nspr security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>nspr</product>
          <product>nss</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1135-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1135.html"/>
        <reference source="CESA" ref_id="CESA-2013:1135"/>
        <reference source="CVE" ref_id="CVE-2013-0791" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0791.html"/>
        <reference source="CVE" ref_id="CVE-2013-1620" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1620.html"/>
        <description>The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:28.443-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:01.967-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:13.573-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="nspr is earlier than 0:4.9.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:91424"/>
          <criterion comment="nspr-devel is earlier than 0:4.9.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:90778"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.14.3-6.el5_9" test_ref="oval:org.mitre.oval:tst:90789"/>
          <criterion comment="nss-tools is earlier than 0:3.14.3-6.el5_9" test_ref="oval:org.mitre.oval:tst:91603"/>
          <criterion comment="nss-devel is earlier than 0:3.14.3-6.el5_9" test_ref="oval:org.mitre.oval:tst:91533"/>
          <criterion comment="nss is earlier than 0:3.14.3-6.el5_9" test_ref="oval:org.mitre.oval:tst:91550"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21082" version="7" class="patch">
      <metadata>
        <title>RHSA-2013:1868: xorg-x11-server security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1868-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1868.html"/>
        <reference source="CESA" ref_id="CESA-2013:1868"/>
        <reference source="CVE" ref_id="CVE-2013-6424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6424.html"/>
        <description>Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:39.355-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:01.809-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:13.427-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21082 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:42.620-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:23.064-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:92119"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:91723"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:91970"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:92093"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:92104"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:91938"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:91734"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:91224"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.101.0.1.el5.centos.2" test_ref="oval:org.mitre.oval:tst:92235"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.101.0.1.el5.centos.2" test_ref="oval:org.mitre.oval:tst:91754"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.101.0.1.el5.centos.2" test_ref="oval:org.mitre.oval:tst:92138"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.101.0.1.el5.centos.2" test_ref="oval:org.mitre.oval:tst:92040"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.101.0.1.el5.centos.2" test_ref="oval:org.mitre.oval:tst:91302"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.101.0.1.el5.centos.2" test_ref="oval:org.mitre.oval:tst:92140"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.101.0.1.el5.centos.2" test_ref="oval:org.mitre.oval:tst:92271"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.101.0.1.el5.centos.2" test_ref="oval:org.mitre.oval:tst:92007"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:92103"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:91238"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:91728"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:91968"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:92165"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:92211"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:92011"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:92142"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:92183"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-23.1.el6.centos" test_ref="oval:org.mitre.oval:tst:92206"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-23.1.el6.centos" test_ref="oval:org.mitre.oval:tst:92000"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.13.0-23.1.el6.centos" test_ref="oval:org.mitre.oval:tst:92298"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-23.1.el6.centos" test_ref="oval:org.mitre.oval:tst:91875"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-23.1.el6.centos" test_ref="oval:org.mitre.oval:tst:92089"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-23.1.el6.centos" test_ref="oval:org.mitre.oval:tst:91984"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-23.1.el6.centos" test_ref="oval:org.mitre.oval:tst:92074"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-23.1.el6.centos" test_ref="oval:org.mitre.oval:tst:91916"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-23.1.el6.centos" test_ref="oval:org.mitre.oval:tst:91846"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21081" version="35" class="patch">
      <metadata>
        <title>RHSA-2013:1818: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1818-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1818.html"/>
        <reference source="CVE" ref_id="CVE-2013-5331" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5331.html"/>
        <reference source="CVE" ref_id="CVE-2013-5332" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5332.html"/>
        <description>Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK &amp; Compiler before 3.9.0.1380 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:12.191-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:01.567-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:13.133-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21081 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:39.906-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:22.856-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21081 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:13.490-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:33.149-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.332-1.el5" test_ref="oval:org.mitre.oval:tst:137609"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.332-1.el6" test_ref="oval:org.mitre.oval:tst:91627"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21079" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:0587: openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0587-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0587.html"/>
        <reference source="CESA" ref_id="CESA-2013:0587"/>
        <reference source="CVE" ref_id="CVE-2012-4929" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4929.html"/>
        <reference source="CVE" ref_id="CVE-2013-0166" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0166.html"/>
        <reference source="CVE" ref_id="CVE-2013-0169" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0169.html"/>
        <description>The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:59:00.653-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:01.401-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:12.983-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:90640"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:90437"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:90553"/>
            <criterion comment="openssl is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:90590"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:90602"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:90398"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:90527"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21078" version="61" class="patch">
      <metadata>
        <title>RHSA-2013:0730: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0730-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0730.html"/>
        <reference source="CVE" ref_id="CVE-2013-1378" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1378.html"/>
        <reference source="CVE" ref_id="CVE-2013-1379" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1379.html"/>
        <reference source="CVE" ref_id="CVE-2013-1380" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1380.html"/>
        <reference source="CVE" ref_id="CVE-2013-2555" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2555.html"/>
        <description>Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on Android 4.x; Adobe AIR before 3.7.0.1530; and Adobe AIR SDK &amp; Compiler before 3.7.0.1530 allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:34.877-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:01.247-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:12.774-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21078 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:17.123-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:32.684-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.280-1.el5" test_ref="oval:org.mitre.oval:tst:137412"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.280-2.el6" test_ref="oval:org.mitre.oval:tst:90863"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21077" version="467" class="patch">
      <metadata>
        <title>RHSA-2013:0625: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0625-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0625.html"/>
        <reference source="CVE" ref_id="CVE-2012-1541" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1541.html"/>
        <reference source="CVE" ref_id="CVE-2012-3213" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3213.html"/>
        <reference source="CVE" ref_id="CVE-2012-3342" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3342.html"/>
        <reference source="CVE" ref_id="CVE-2012-5085" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5085.html"/>
        <reference source="CVE" ref_id="CVE-2013-0351" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0351.html"/>
        <reference source="CVE" ref_id="CVE-2013-0409" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0409.html"/>
        <reference source="CVE" ref_id="CVE-2013-0419" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0419.html"/>
        <reference source="CVE" ref_id="CVE-2013-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0423.html"/>
        <reference source="CVE" ref_id="CVE-2013-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0424.html"/>
        <reference source="CVE" ref_id="CVE-2013-0425" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0425.html"/>
        <reference source="CVE" ref_id="CVE-2013-0426" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0426.html"/>
        <reference source="CVE" ref_id="CVE-2013-0427" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0427.html"/>
        <reference source="CVE" ref_id="CVE-2013-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0428.html"/>
        <reference source="CVE" ref_id="CVE-2013-0432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0432.html"/>
        <reference source="CVE" ref_id="CVE-2013-0433" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0433.html"/>
        <reference source="CVE" ref_id="CVE-2013-0434" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0434.html"/>
        <reference source="CVE" ref_id="CVE-2013-0435" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0435.html"/>
        <reference source="CVE" ref_id="CVE-2013-0438" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0438.html"/>
        <reference source="CVE" ref_id="CVE-2013-0440" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0440.html"/>
        <reference source="CVE" ref_id="CVE-2013-0441" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0441.html"/>
        <reference source="CVE" ref_id="CVE-2013-0442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0442.html"/>
        <reference source="CVE" ref_id="CVE-2013-0443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0443.html"/>
        <reference source="CVE" ref_id="CVE-2013-0445" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0445.html"/>
        <reference source="CVE" ref_id="CVE-2013-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0446.html"/>
        <reference source="CVE" ref_id="CVE-2013-0450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0450.html"/>
        <reference source="CVE" ref_id="CVE-2013-0809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0809.html"/>
        <reference source="CVE" ref_id="CVE-2013-1473" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1473.html"/>
        <reference source="CVE" ref_id="CVE-2013-1476" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1476.html"/>
        <reference source="CVE" ref_id="CVE-2013-1478" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1478.html"/>
        <reference source="CVE" ref_id="CVE-2013-1480" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1480.html"/>
        <reference source="CVE" ref_id="CVE-2013-1481" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1481.html"/>
        <reference source="CVE" ref_id="CVE-2013-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1486.html"/>
        <reference source="CVE" ref_id="CVE-2013-1487" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1487.html"/>
        <reference source="CVE" ref_id="CVE-2013-1493" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1493.html"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:56.595-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:01.045-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:12.494-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21077 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:17.697-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:29.992-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.13.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137838"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.13.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137346"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.13.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137593"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.13.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137842"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.13.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137639"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.13.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137758"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.13.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137583"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.13.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137672"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:90948"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:90391"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:90795"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:90772"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:90660"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:90411"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:90935"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21071" version="211" class="patch">
      <metadata>
        <title>RHSA-2012:1482: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1482-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1482.html"/>
        <reference source="CESA" ref_id="CESA-2012:1482"/>
        <reference source="CVE" ref_id="CVE-2012-4201" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4201.html"/>
        <reference source="CVE" ref_id="CVE-2012-4202" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4202.html"/>
        <reference source="CVE" ref_id="CVE-2012-4207" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4207.html"/>
        <reference source="CVE" ref_id="CVE-2012-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4209.html"/>
        <reference source="CVE" ref_id="CVE-2012-4210" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4210.html"/>
        <reference source="CVE" ref_id="CVE-2012-4214" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4214.html"/>
        <reference source="CVE" ref_id="CVE-2012-4215" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4215.html"/>
        <reference source="CVE" ref_id="CVE-2012-4216" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4216.html"/>
        <reference source="CVE" ref_id="CVE-2012-5829" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5829.html"/>
        <reference source="CVE" ref_id="CVE-2012-5830" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5830.html"/>
        <reference source="CVE" ref_id="CVE-2012-5833" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5833.html"/>
        <reference source="CVE" ref_id="CVE-2012-5835" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5835.html"/>
        <reference source="CVE" ref_id="CVE-2012-5839" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5839.html"/>
        <reference source="CVE" ref_id="CVE-2012-5840" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5840.html"/>
        <reference source="CVE" ref_id="CVE-2012-5841" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5841.html"/>
        <reference source="CVE" ref_id="CVE-2012-5842" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5842.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:41.005-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:28.686-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:46.000-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:94503"/>
            <criterion comment="xulrunner is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:94930"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:10.0.11-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94533"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:94399"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:94944"/>
            <criterion comment="xulrunner is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:94847"/>
            <criterion comment="firefox is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:94355"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.11-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94784"/>
            <criterion comment="xulrunner is earlier than 0:10.0.11-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94666"/>
            <criterion comment="firefox is earlier than 0:10.0.11-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94518"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21067" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:0815: httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0815-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0815.html"/>
        <reference source="CESA" ref_id="CESA-2013:0815"/>
        <reference source="CVE" ref_id="CVE-2012-3499" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3499.html"/>
        <reference source="CVE" ref_id="CVE-2012-4558" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4558.html"/>
        <reference source="CVE" ref_id="CVE-2013-1862" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1862.html"/>
        <description>mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:24.306-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:59.298-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:10.580-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-devel is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:91174"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:91249"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:90739"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:91193"/>
            <criterion comment="httpd is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:91064"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-devel is earlier than 0:2.2.15-28.el6.centos" test_ref="oval:org.mitre.oval:tst:91852"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-28.el6.centos" test_ref="oval:org.mitre.oval:tst:91823"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-28.el6.centos" test_ref="oval:org.mitre.oval:tst:92124"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.15-28.el6.centos" test_ref="oval:org.mitre.oval:tst:91946"/>
            <criterion comment="httpd is earlier than 0:2.2.15-28.el6.centos" test_ref="oval:org.mitre.oval:tst:91985"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-devel is earlier than 0:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:90743"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:91260"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:90956"/>
            <criterion comment="httpd is earlier than 0:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:90812"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-devel is earlier than 0:2.2.3-78.el5.centos" test_ref="oval:org.mitre.oval:tst:92008"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.3-78.el5.centos" test_ref="oval:org.mitre.oval:tst:92248"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-78.el5.centos" test_ref="oval:org.mitre.oval:tst:91618"/>
            <criterion comment="httpd is earlier than 0:2.2.3-78.el5.centos" test_ref="oval:org.mitre.oval:tst:91837"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21060" version="7" class="patch">
      <metadata>
        <title>RHSA-2013:1869: pixman security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>pixman</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1869-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1869.html"/>
        <reference source="CESA" ref_id="CESA-2013:1869"/>
        <reference source="CVE" ref_id="CVE-2013-6425" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6425.html"/>
        <description>Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:15.100-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:58.780-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:10.008-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21060 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:40.360-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:21.111-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="pixman-devel is earlier than 0:0.22.0-2.2.el5_10" test_ref="oval:org.mitre.oval:tst:92053"/>
            <criterion comment="pixman is earlier than 0:0.22.0-2.2.el5_10" test_ref="oval:org.mitre.oval:tst:92234"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="pixman-devel is earlier than 0:0.26.2-5.1.el6_5" test_ref="oval:org.mitre.oval:tst:92222"/>
            <criterion comment="pixman is earlier than 0:0.26.2-5.1.el6_5" test_ref="oval:org.mitre.oval:tst:92046"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21056" version="94" class="patch">
      <metadata>
        <title>RHSA-2011:0857: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0857-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0857.html"/>
        <reference source="CESA" ref_id="CESA-2011:0857"/>
        <reference source="CVE" ref_id="CVE-2011-0862" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0862.html"/>
        <reference source="CVE" ref_id="CVE-2011-0864" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0864.html"/>
        <reference source="CVE" ref_id="CVE-2011-0865" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0865.html"/>
        <reference source="CVE" ref_id="CVE-2011-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0867.html"/>
        <reference source="CVE" ref_id="CVE-2011-0868" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0868.html"/>
        <reference source="CVE" ref_id="CVE-2011-0869" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0869.html"/>
        <reference source="CVE" ref_id="CVE-2011-0871" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0871.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Swing.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:04.957-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:28.155-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:45.280-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.22.1.9.8.el5_6" test_ref="oval:org.mitre.oval:tst:98089"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.22.1.9.8.el5_6" test_ref="oval:org.mitre.oval:tst:97707"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.22.1.9.8.el5_6" test_ref="oval:org.mitre.oval:tst:97935"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.22.1.9.8.el5_6" test_ref="oval:org.mitre.oval:tst:97992"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.22.1.9.8.el5_6" test_ref="oval:org.mitre.oval:tst:98095"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21052" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0568: dbus-glib security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>dbus-glib</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0568-03" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0568.html"/>
        <reference source="CESA" ref_id="CESA-2013:0568"/>
        <reference source="CVE" ref_id="CVE-2013-0292" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0292.html"/>
        <description>The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:00.813-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:58.186-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:09.699-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dbus-glib is earlier than 0:0.86-6.el6_4" test_ref="oval:org.mitre.oval:tst:90708"/>
            <criterion comment="dbus-glib-devel is earlier than 0:0.86-6.el6_4" test_ref="oval:org.mitre.oval:tst:90455"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dbus-glib is earlier than 0:0.86-6.el6" test_ref="oval:org.mitre.oval:tst:91997"/>
            <criterion comment="dbus-glib-devel is earlier than 0:0.86-6.el6" test_ref="oval:org.mitre.oval:tst:91937"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dbus-glib is earlier than 0:0.73-11.el5_9" test_ref="oval:org.mitre.oval:tst:90436"/>
            <criterion comment="dbus-glib-devel is earlier than 0:0.73-11.el5_9" test_ref="oval:org.mitre.oval:tst:90314"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21046" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0270: jakarta-commons-httpclient security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>jakarta-commons-httpclient</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0270-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0270.html"/>
        <reference source="CESA" ref_id="CESA-2013:0270"/>
        <reference source="CVE" ref_id="CVE-2012-5783" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5783.html"/>
        <description>Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:04.852-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:57.867-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:09.338-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:90251"/>
            <criterion comment="jakarta-commons-httpclient is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:89947"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:90456"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:90471"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:90319"/>
            <criterion comment="jakarta-commons-httpclient is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:90312"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:90497"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:90286"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21040" version="579" class="patch">
      <metadata>
        <title>RHSA-2013:0626: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0626-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0626.html"/>
        <reference source="CVE" ref_id="CVE-2012-1541" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1541.html"/>
        <reference source="CVE" ref_id="CVE-2012-3174" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3174.html"/>
        <reference source="CVE" ref_id="CVE-2012-3213" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3213.html"/>
        <reference source="CVE" ref_id="CVE-2012-3342" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3342.html"/>
        <reference source="CVE" ref_id="CVE-2012-5085" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5085.html"/>
        <reference source="CVE" ref_id="CVE-2013-0351" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0351.html"/>
        <reference source="CVE" ref_id="CVE-2013-0409" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0409.html"/>
        <reference source="CVE" ref_id="CVE-2013-0419" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0419.html"/>
        <reference source="CVE" ref_id="CVE-2013-0422" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0422.html"/>
        <reference source="CVE" ref_id="CVE-2013-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0423.html"/>
        <reference source="CVE" ref_id="CVE-2013-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0424.html"/>
        <reference source="CVE" ref_id="CVE-2013-0425" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0425.html"/>
        <reference source="CVE" ref_id="CVE-2013-0426" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0426.html"/>
        <reference source="CVE" ref_id="CVE-2013-0427" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0427.html"/>
        <reference source="CVE" ref_id="CVE-2013-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0428.html"/>
        <reference source="CVE" ref_id="CVE-2013-0431" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0431.html"/>
        <reference source="CVE" ref_id="CVE-2013-0432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0432.html"/>
        <reference source="CVE" ref_id="CVE-2013-0433" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0433.html"/>
        <reference source="CVE" ref_id="CVE-2013-0434" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0434.html"/>
        <reference source="CVE" ref_id="CVE-2013-0435" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0435.html"/>
        <reference source="CVE" ref_id="CVE-2013-0437" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0437.html"/>
        <reference source="CVE" ref_id="CVE-2013-0438" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0438.html"/>
        <reference source="CVE" ref_id="CVE-2013-0440" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0440.html"/>
        <reference source="CVE" ref_id="CVE-2013-0441" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0441.html"/>
        <reference source="CVE" ref_id="CVE-2013-0442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0442.html"/>
        <reference source="CVE" ref_id="CVE-2013-0443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0443.html"/>
        <reference source="CVE" ref_id="CVE-2013-0444" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0444.html"/>
        <reference source="CVE" ref_id="CVE-2013-0445" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0445.html"/>
        <reference source="CVE" ref_id="CVE-2013-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0446.html"/>
        <reference source="CVE" ref_id="CVE-2013-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0449.html"/>
        <reference source="CVE" ref_id="CVE-2013-0450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0450.html"/>
        <reference source="CVE" ref_id="CVE-2013-0809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0809.html"/>
        <reference source="CVE" ref_id="CVE-2013-1473" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1473.html"/>
        <reference source="CVE" ref_id="CVE-2013-1476" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1476.html"/>
        <reference source="CVE" ref_id="CVE-2013-1478" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1478.html"/>
        <reference source="CVE" ref_id="CVE-2013-1480" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1480.html"/>
        <reference source="CVE" ref_id="CVE-2013-1484" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1484.html"/>
        <reference source="CVE" ref_id="CVE-2013-1485" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1485.html"/>
        <reference source="CVE" ref_id="CVE-2013-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1486.html"/>
        <reference source="CVE" ref_id="CVE-2013-1487" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1487.html"/>
        <reference source="CVE" ref_id="CVE-2013-1493" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1493.html"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:58.469-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:56.474-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:07.303-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21040 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:33.045-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:26.843-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.4.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137621"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.4.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137785"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.4.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137762"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.4.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137817"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.4.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137767"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.4.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137520"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.4.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:90834"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.4.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:90994"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.4.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:90918"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.4.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:90840"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.4.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:90745"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.4.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:90989"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21039" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0127: libvirt security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0127-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0127.html"/>
        <reference source="CESA" ref_id="CESA-2013:0127"/>
        <reference source="CVE" ref_id="CVE-2012-2693" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2693.html"/>
        <description>libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:21.216-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:56.382-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:07.192-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libvirt-python is earlier than 0:0.8.2-29.el5" test_ref="oval:org.mitre.oval:tst:90072"/>
          <criterion comment="libvirt is earlier than 0:0.8.2-29.el5" test_ref="oval:org.mitre.oval:tst:89991"/>
          <criterion comment="libvirt-devel is earlier than 0:0.8.2-29.el5" test_ref="oval:org.mitre.oval:tst:90217"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21038" version="143" class="patch">
      <metadata>
        <title>RHSA-2013:0821: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0821-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0821.html"/>
        <reference source="CESA" ref_id="CESA-2013:0821"/>
        <reference source="CVE" ref_id="CVE-2013-0801" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0801.html"/>
        <reference source="CVE" ref_id="CVE-2013-1670" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1670.html"/>
        <reference source="CVE" ref_id="CVE-2013-1674" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1674.html"/>
        <reference source="CVE" ref_id="CVE-2013-1675" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1675.html"/>
        <reference source="CVE" ref_id="CVE-2013-1676" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1676.html"/>
        <reference source="CVE" ref_id="CVE-2013-1677" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1677.html"/>
        <reference source="CVE" ref_id="CVE-2013-1678" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1678.html"/>
        <reference source="CVE" ref_id="CVE-2013-1679" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1679.html"/>
        <reference source="CVE" ref_id="CVE-2013-1680" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1680.html"/>
        <reference source="CVE" ref_id="CVE-2013-1681" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1681.html"/>
        <description>Use-after-free vulnerability in the nsContentUtils::RemoveScriptBlocker function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:24.362-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:55.938-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:06.782-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.6-2.el6_4" test_ref="oval:org.mitre.oval:tst:91173"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.6-2.el6.centos" test_ref="oval:org.mitre.oval:tst:91935"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:17.0.6-1.el5_9" test_ref="oval:org.mitre.oval:tst:90899"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:17.0.6-1.el5.centos" test_ref="oval:org.mitre.oval:tst:91580"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21037" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1409: xinetd security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>xinetd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1409-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1409.html"/>
        <reference source="CESA" ref_id="CESA-2013:1409"/>
        <reference source="CVE" ref_id="CVE-2013-4342" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4342.html"/>
        <description>xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:54.134-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:55.831-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:06.638-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criterion comment="xinetd is earlier than 2:2.3.14-39.el6_4" test_ref="oval:org.mitre.oval:tst:91670"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="xinetd is earlier than 2:2.3.14-20.el5_10" test_ref="oval:org.mitre.oval:tst:91703"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21035" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1050: php53 security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>php53</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1050-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1050.html"/>
        <reference source="CESA" ref_id="CESA-2013:1050"/>
        <reference source="CVE" ref_id="CVE-2013-4113" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4113.html"/>
        <description>ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:21.936-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:55.679-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:06.468-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="php53-ldap is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:91393"/>
          <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:91347"/>
          <criterion comment="php53-common is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:91382"/>
          <criterion comment="php53 is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:91485"/>
          <criterion comment="php53-snmp is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:91304"/>
          <criterion comment="php53-process is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:91427"/>
          <criterion comment="php53-bcmath is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:91409"/>
          <criterion comment="php53-dba is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:91439"/>
          <criterion comment="php53-imap is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:91534"/>
          <criterion comment="php53-odbc is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:91336"/>
          <criterion comment="php53-soap is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:91180"/>
          <criterion comment="php53-pgsql is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:91504"/>
          <criterion comment="php53-pspell is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:91160"/>
          <criterion comment="php53-mysql is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:90871"/>
          <criterion comment="php53-cli is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:91089"/>
          <criterion comment="php53-intl is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:91493"/>
          <criterion comment="php53-xml is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:91502"/>
          <criterion comment="php53-pdo is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:91159"/>
          <criterion comment="php53-gd is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:91559"/>
          <criterion comment="php53-mbstring is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:91202"/>
          <criterion comment="php53-devel is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:90788"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21027" version="33" class="patch">
      <metadata>
        <title>RHSA-2013:0551: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0551-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0551.html"/>
        <reference source="CVE" ref_id="CVE-2013-0640" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0640.html"/>
        <reference source="CVE" ref_id="CVE-2013-0641" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0641.html"/>
        <description>Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary code via a crafted PDF document, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:23.145-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:55.258-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:05.963-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21027 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:30.328-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:26.242-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="acroread is earlier than 0:9.5.4-1.el5_9" test_ref="oval:org.mitre.oval:tst:137432"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.4-1.el5_9" test_ref="oval:org.mitre.oval:tst:137180"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="acroread is earlier than 0:9.5.4-1.el6" test_ref="oval:org.mitre.oval:tst:90664"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.4-1.el6" test_ref="oval:org.mitre.oval:tst:90649"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21025" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0120: quota security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>quota</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0120-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0120.html"/>
        <reference source="CESA" ref_id="CESA-2013:0120"/>
        <reference source="CVE" ref_id="CVE-2012-3417" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3417.html"/>
        <description>The good_client function in rquotad (rquota_svc.c) in Linux DiskQuota (aka quota) before 3.17 invokes the hosts_ctl function the first time without a host name, which might allow remote attackers to bypass TCP Wrappers rules in hosts.deny.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:20.458-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:54.893-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:05.822-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="quota is earlier than 1:3.13-8.el5" test_ref="oval:org.mitre.oval:tst:90184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21022" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0180: mysql security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0180-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0180.html"/>
        <reference source="CESA" ref_id="CESA-2013:0180"/>
        <reference source="CVE" ref_id="CVE-2012-2749" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2749.html"/>
        <reference source="CVE" ref_id="CVE-2012-5611" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5611.html"/>
        <description>Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FILE command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:59:08.556-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:54.687-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:05.671-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mysql-test is earlier than 0:5.0.95-5.el5_9" test_ref="oval:org.mitre.oval:tst:89862"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.95-5.el5_9" test_ref="oval:org.mitre.oval:tst:90180"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.95-5.el5_9" test_ref="oval:org.mitre.oval:tst:90421"/>
          <criterion comment="mysql is earlier than 0:5.0.95-5.el5_9" test_ref="oval:org.mitre.oval:tst:90397"/>
          <criterion comment="mysql-server is earlier than 0:5.0.95-5.el5_9" test_ref="oval:org.mitre.oval:tst:90133"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21017" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:0130: httpd security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0130-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0130.html"/>
        <reference source="CESA" ref_id="CESA-2013:0130"/>
        <reference source="CVE" ref_id="CVE-2008-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0455.html"/>
        <reference source="CVE" ref_id="CVE-2008-0456" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0456.html"/>
        <reference source="CVE" ref_id="CVE-2012-2687" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2687.html"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:19.655-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:54.502-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:05.461-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-manual is earlier than 0:2.2.3-74.el5" test_ref="oval:org.mitre.oval:tst:90241"/>
            <criterion comment="httpd is earlier than 0:2.2.3-74.el5" test_ref="oval:org.mitre.oval:tst:90143"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-74.el5" test_ref="oval:org.mitre.oval:tst:90124"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-74.el5" test_ref="oval:org.mitre.oval:tst:90269"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-manual is earlier than 0:2.2.3-74.el5.centos" test_ref="oval:org.mitre.oval:tst:92044"/>
            <criterion comment="httpd is earlier than 0:2.2.3-74.el5.centos" test_ref="oval:org.mitre.oval:tst:91895"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-74.el5.centos" test_ref="oval:org.mitre.oval:tst:91699"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-74.el5.centos" test_ref="oval:org.mitre.oval:tst:92159"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21013" version="42" class="patch">
      <metadata>
        <title>RHSA-2012:0545: ImageMagick security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>ImageMagick</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0545-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0545.html"/>
        <reference source="CESA" ref_id="CESA-2012:0545"/>
        <reference source="CVE" ref_id="CVE-2012-0247" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0247.html"/>
        <reference source="CVE" ref_id="CVE-2012-0248" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0248.html"/>
        <reference source="CVE" ref_id="CVE-2012-0260" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0260.html"/>
        <description>The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:12.408-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:26.858-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:43.952-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="ImageMagick-devel is earlier than 0:6.2.8.0-15.el5_8" test_ref="oval:org.mitre.oval:tst:93190"/>
          <criterion comment="ImageMagick-c++ is earlier than 0:6.2.8.0-15.el5_8" test_ref="oval:org.mitre.oval:tst:93180"/>
          <criterion comment="ImageMagick-c++-devel is earlier than 0:6.2.8.0-15.el5_8" test_ref="oval:org.mitre.oval:tst:93145"/>
          <criterion comment="ImageMagick is earlier than 0:6.2.8.0-15.el5_8" test_ref="oval:org.mitre.oval:tst:93225"/>
          <criterion comment="ImageMagick-perl is earlier than 0:6.2.8.0-15.el5_8" test_ref="oval:org.mitre.oval:tst:93236"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21012" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0131: gnome-vfs2 security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gnome-vfs2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0131-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0131.html"/>
        <reference source="CESA" ref_id="CESA-2013:0131"/>
        <reference source="CVE" ref_id="CVE-2009-2473" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2473.html"/>
        <description>neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:47.037-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:54.401-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:05.334-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="gnome-vfs2 is earlier than 0:2.16.2-10.el5" test_ref="oval:org.mitre.oval:tst:89720"/>
          <criterion comment="gnome-vfs2-devel is earlier than 0:2.16.2-10.el5" test_ref="oval:org.mitre.oval:tst:89897"/>
          <criterion comment="gnome-vfs2-smb is earlier than 0:2.16.2-10.el5" test_ref="oval:org.mitre.oval:tst:90192"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21011" version="304" class="patch">
      <metadata>
        <title>RHSA-2012:1466: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1466-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1466.html"/>
        <reference source="CVE" ref_id="CVE-2012-0547" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0547.html"/>
        <reference source="CVE" ref_id="CVE-2012-1531" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1531.html"/>
        <reference source="CVE" ref_id="CVE-2012-1532" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1532.html"/>
        <reference source="CVE" ref_id="CVE-2012-1533" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1533.html"/>
        <reference source="CVE" ref_id="CVE-2012-1682" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1682.html"/>
        <reference source="CVE" ref_id="CVE-2012-3143" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3143.html"/>
        <reference source="CVE" ref_id="CVE-2012-3159" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3159.html"/>
        <reference source="CVE" ref_id="CVE-2012-3216" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3216.html"/>
        <reference source="CVE" ref_id="CVE-2012-4820" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4820.html"/>
        <reference source="CVE" ref_id="CVE-2012-4822" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4822.html"/>
        <reference source="CVE" ref_id="CVE-2012-4823" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4823.html"/>
        <reference source="CVE" ref_id="CVE-2012-5068" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5068.html"/>
        <reference source="CVE" ref_id="CVE-2012-5069" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5069.html"/>
        <reference source="CVE" ref_id="CVE-2012-5071" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5071.html"/>
        <reference source="CVE" ref_id="CVE-2012-5072" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5072.html"/>
        <reference source="CVE" ref_id="CVE-2012-5073" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5073.html"/>
        <reference source="CVE" ref_id="CVE-2012-5075" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5075.html"/>
        <reference source="CVE" ref_id="CVE-2012-5079" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5079.html"/>
        <reference source="CVE" ref_id="CVE-2012-5081" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5081.html"/>
        <reference source="CVE" ref_id="CVE-2012-5083" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5083.html"/>
        <reference source="CVE" ref_id="CVE-2012-5084" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5084.html"/>
        <reference source="CVE" ref_id="CVE-2012-5089" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5089.html"/>
        <reference source="CVE" ref_id="CVE-2013-1475" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1475.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "IIOP type reuse management" in ObjectStreamClass.java.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:40.068-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:26.650-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:43.165-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21011 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:25.332-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:24.336-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.12.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137931"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.12.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137756"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.12.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137957"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.12.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137093"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.12.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137900"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.12.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137918"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.12.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137791"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.12.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137982"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.12.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94420"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.12.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94154"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.12.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94688"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.12.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94868"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.12.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94715"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.12.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94806"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.12.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94334"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21010" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1779: mod_nss security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>mod_nss</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1779-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1779.html"/>
        <reference source="CESA" ref_id="CESA-2013:1779"/>
        <reference source="CVE" ref_id="CVE-2013-4566" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4566.html"/>
        <description>mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory context, which allows remote attackers to bypass intended access restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:20.086-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:54.295-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:05.203-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="mod_nss is earlier than 0:1.0.8-8.el5_10" test_ref="oval:org.mitre.oval:tst:91316"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="mod_nss is earlier than 0:1.0.8-19.el6_5" test_ref="oval:org.mitre.oval:tst:91691"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21009" version="6" class="patch">
      <metadata>
        <title>RHSA-2013:0149: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0149-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0149.html"/>
        <reference source="CVE" ref_id="CVE-2013-0630" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0630.html"/>
        <description>Buffer overflow in Adobe Flash Player before 10.3.183.50 and 11.x before 11.5.502.146 on Windows and Mac OS X, before 10.3.183.50 and 11.x before 11.2.202.261 on Linux, before 11.1.111.31 on Android 2.x and 3.x, and before 11.1.115.36 on Android 4.x; Adobe AIR before 3.5.0.1060; and Adobe AIR SDK before 3.5.0.1060 allows attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:59:01.231-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:54.205-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:05.106-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21009 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:05.301-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:23.969-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.261-1.el5" test_ref="oval:org.mitre.oval:tst:137548"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.261-1.el6" test_ref="oval:org.mitre.oval:tst:90331"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21008" version="5" class="patch">
      <metadata>
        <title>RHSA-2013:1142: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1142-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1142.html"/>
        <reference source="CESA" ref_id="CESA-2013:1142"/>
        <reference source="CVE" ref_id="CVE-2013-1701" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1701.html"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed content. Malicious
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2013-1701)

A flaw was found in the way Thunderbird generated Certificate Request
Message Format (CRMF) requests. An attacker could use this flaw to perform
cross-site scripting (XSS) attacks or execute arbitrary code with the
privileges of the user running Thunderbird. (CVE-2013-1710)

A flaw was found in the way Thunderbird handled the interaction between
frames and browser history. An attacker could use this flaw to trick
Thunderbird into treating malicious content as if it came from the browser
history, allowing for XSS attacks. (CVE-2013-1709)

It was found that the same-origin policy could be bypassed due to the way
Uniform Resource Identifiers (URI) were checked in JavaScript. An attacker
could use this flaw to perform XSS attacks, or install malicious add-ons
from third-party pages. (CVE-2013-1713)

It was found that web workers could bypass the same-origin policy. An
attacker could use this flaw to perform XSS attacks. (CVE-2013-1714)

It was found that, in certain circumstances, Thunderbird incorrectly
handled Java applets. If a user launched an untrusted Java applet via
Thunderbird, the applet could use this flaw to obtain read-only access to
files on the user's local system. (CVE-2013-1717)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Jeff Gilbert, Henrik Skupin, moz_bug_r_a4, Cody
Crews, Federico Lanusse, and Georgi Guninski as the original reporters of
these issues.

Note: All of the above issues cannot be exploited by a specially-crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 17.0.8 ESR, which corrects these issues. After
installing the update, Thunderbird must be restarted for the changes to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:21.437-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:54.093-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:04.962-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21008 - modified Vulnerability definition of CVE-2013-1701 for CentOS" date="2014-05-30T10:40:00.295-04:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2014-05-30T10:42:17.655-04:00">INTERIM</status_change>
            <status_change date="2014-06-16T04:00:08.881-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.8-5.el6_4" test_ref="oval:org.mitre.oval:tst:91629"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.8-5.el6.centos" test_ref="oval:org.mitre.oval:tst:92027"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:17.0.8-5.el5_9" test_ref="oval:org.mitre.oval:tst:91431"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:17.0.8-5.el5.centos" test_ref="oval:org.mitre.oval:tst:91287"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21004" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0614: xulrunner security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0614-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0614.html"/>
        <reference source="CESA" ref_id="CESA-2013:0614"/>
        <reference source="CVE" ref_id="CVE-2013-0787" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0787.html"/>
        <description>Use-after-free vulnerability in the nsEditor::IsPreformatted function in editor/libeditor/base/nsEditor.cpp in Mozilla Firefox before 19.0.2, Firefox ESR 17.x before 17.0.4, Thunderbird before 17.0.4, Thunderbird ESR 17.x before 17.0.4, and SeaMonkey before 2.16.1 allows remote attackers to execute arbitrary code via vectors involving an execCommand call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:34.917-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:53.904-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:04.718-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-2.el6_4" test_ref="oval:org.mitre.oval:tst:90919"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-2.el6_4" test_ref="oval:org.mitre.oval:tst:90537"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-2.el6.centos" test_ref="oval:org.mitre.oval:tst:92208"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-2.el6.centos" test_ref="oval:org.mitre.oval:tst:92041"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-2.el5_9" test_ref="oval:org.mitre.oval:tst:90718"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-2.el5_9" test_ref="oval:org.mitre.oval:tst:90957"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21001" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0668: boost security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>boost</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0668-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0668.html"/>
        <reference source="CESA" ref_id="CESA-2013:0668"/>
        <reference source="CVE" ref_id="CVE-2012-2677" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2677.html"/>
        <description>Integer overflow in the ordered_malloc function in boost/pool/pool.hpp in Boost Pool before 3.9 makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large memory chunk size value, which causes less memory to be allocated than expected.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:33.316-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:53.648-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:04.323-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="boost-graph-mpich2 is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90648"/>
            <criterion comment="boost-graph-openmpi is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90849"/>
            <criterion comment="boost-mpich2 is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:91061"/>
            <criterion comment="boost-test is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:91041"/>
            <criterion comment="boost-graph is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90792"/>
            <criterion comment="boost is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90847"/>
            <criterion comment="boost-mpich2-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:91036"/>
            <criterion comment="boost-wave is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90430"/>
            <criterion comment="boost-filesystem is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90591"/>
            <criterion comment="boost-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:91046"/>
            <criterion comment="boost-thread is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90564"/>
            <criterion comment="boost-mpich2-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90892"/>
            <criterion comment="boost-openmpi is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90304"/>
            <criterion comment="boost-static is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90763"/>
            <criterion comment="boost-doc is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:91047"/>
            <criterion comment="boost-regex is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90790"/>
            <criterion comment="boost-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90922"/>
            <criterion comment="boost-openmpi-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90867"/>
            <criterion comment="boost-serialization is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90888"/>
            <criterion comment="boost-system is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:91086"/>
            <criterion comment="boost-iostreams is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90569"/>
            <criterion comment="boost-signals is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90092"/>
            <criterion comment="boost-program-options is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90945"/>
            <criterion comment="boost-openmpi-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:91002"/>
            <criterion comment="boost-date-time is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90972"/>
            <criterion comment="boost-math is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90372"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="boost is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:90822"/>
            <criterion comment="boost-doc is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:90623"/>
            <criterion comment="boost-devel is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:91003"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20998" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0122: tcl security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>tcl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0122-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0122.html"/>
        <reference source="CESA" ref_id="CESA-2013:0122"/>
        <reference source="CVE" ref_id="CVE-2007-4772" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4772.html"/>
        <reference source="CVE" ref_id="CVE-2007-6067" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6067.html"/>
        <description>Algorithmic complexity vulnerability in the regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (memory consumption) via a crafted "complex" regular expression with doubly-nested states.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:35.449-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:53.133-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:03.783-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tcl-devel is earlier than 0:8.4.13-6.el5" test_ref="oval:org.mitre.oval:tst:89559"/>
          <criterion comment="tcl is earlier than 0:8.4.13-6.el5" test_ref="oval:org.mitre.oval:tst:90118"/>
          <criterion comment="tcl-html is earlier than 0:8.4.13-6.el5" test_ref="oval:org.mitre.oval:tst:89344"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20995" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0133: hplip3 security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>hplip3</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0133-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0133.html"/>
        <reference source="CESA" ref_id="CESA-2013:0133"/>
        <reference source="CVE" ref_id="CVE-2011-2722" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2722.html"/>
        <description>The send_data_to_stdout function in prnt/hpijs/hpcupsfax.cpp in HP Linux Imaging and Printing (HPLIP) 3.x before 3.11.10 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hpcupsfax.out temporary file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:11.036-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:53.023-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:03.573-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="hplip3-gui is earlier than 0:3.9.8-15.el5" test_ref="oval:org.mitre.oval:tst:90006"/>
          <criterion comment="hplip3-common is earlier than 0:3.9.8-15.el5" test_ref="oval:org.mitre.oval:tst:90358"/>
          <criterion comment="hplip3 is earlier than 0:3.9.8-15.el5" test_ref="oval:org.mitre.oval:tst:90264"/>
          <criterion comment="hpijs3 is earlier than 0:3.9.8-15.el5" test_ref="oval:org.mitre.oval:tst:90311"/>
          <criterion comment="hplip3-libs is earlier than 0:3.9.8-15.el5" test_ref="oval:org.mitre.oval:tst:90279"/>
          <criterion comment="libsane-hpaio3 is earlier than 0:3.9.8-15.el5" test_ref="oval:org.mitre.oval:tst:89383"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20994" version="59" class="patch">
      <metadata>
        <title>RHSA-2013:0685: perl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>perl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0685-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0685.html"/>
        <reference source="CESA" ref_id="CESA-2013:0685"/>
        <reference source="CVE" ref_id="CVE-2012-5195" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5195.html"/>
        <reference source="CVE" ref_id="CVE-2012-5526" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5526.html"/>
        <reference source="CVE" ref_id="CVE-2012-6329" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6329.html"/>
        <reference source="CVE" ref_id="CVE-2013-1667" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1667.html"/>
        <description>The rehash mechanism in Perl 5.8.2 through 5.16.x allows context-dependent attackers to cause a denial of service (memory consumption and crash) via a crafted hash key.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:41.927-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:52.725-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:03.149-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="perl-libs is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:91075"/>
            <criterion comment="perl-suidperl is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:90908"/>
            <criterion comment="perl-core is earlier than 0:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:90425"/>
            <criterion comment="perl-Package-Constants is earlier than 1:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:91084"/>
            <criterion comment="perl-ExtUtils-CBuilder is earlier than 1:0.27-130.el6_4" test_ref="oval:org.mitre.oval:tst:91083"/>
            <criterion comment="perl-IO-Compress-Base is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:90250"/>
            <criterion comment="perl-Time-HiRes is earlier than 4:1.9721-130.el6_4" test_ref="oval:org.mitre.oval:tst:90221"/>
            <criterion comment="perl-CGI is earlier than 0:3.51-130.el6_4" test_ref="oval:org.mitre.oval:tst:90508"/>
            <criterion comment="perl-Log-Message-Simple is earlier than 0:0.04-130.el6_4" test_ref="oval:org.mitre.oval:tst:91060"/>
            <criterion comment="perl-Archive-Extract is earlier than 1:0.38-130.el6_4" test_ref="oval:org.mitre.oval:tst:90881"/>
            <criterion comment="perl-version is earlier than 3:0.77-130.el6_4" test_ref="oval:org.mitre.oval:tst:90582"/>
            <criterion comment="perl-ExtUtils-ParseXS is earlier than 1:2.2003.0-130.el6_4" test_ref="oval:org.mitre.oval:tst:90820"/>
            <criterion comment="perl-Test-Simple is earlier than 0:0.92-130.el6_4" test_ref="oval:org.mitre.oval:tst:90507"/>
            <criterion comment="perl-Compress-Raw-Zlib is earlier than 1:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:90612"/>
            <criterion comment="perl-Module-Loaded is earlier than 1:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:90741"/>
            <criterion comment="perl-IO-Compress-Bzip2 is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:90984"/>
            <criterion comment="perl-Module-Pluggable is earlier than 1:3.90-130.el6_4" test_ref="oval:org.mitre.oval:tst:90853"/>
            <criterion comment="perl-Test-Harness is earlier than 0:3.17-130.el6_4" test_ref="oval:org.mitre.oval:tst:90798"/>
            <criterion comment="perl-Pod-Escapes is earlier than 1:1.04-130.el6_4" test_ref="oval:org.mitre.oval:tst:90744"/>
            <criterion comment="perl-parent is earlier than 1:0.221-130.el6_4" test_ref="oval:org.mitre.oval:tst:90958"/>
            <criterion comment="perl-IO-Compress-Zlib is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:90727"/>
            <criterion comment="perl-CPANPLUS is earlier than 0:0.88-130.el6_4" test_ref="oval:org.mitre.oval:tst:91021"/>
            <criterion comment="perl-Pod-Simple is earlier than 1:3.13-130.el6_4" test_ref="oval:org.mitre.oval:tst:90796"/>
            <criterion comment="perl-Module-Load is earlier than 1:0.16-130.el6_4" test_ref="oval:org.mitre.oval:tst:90826"/>
            <criterion comment="perl-File-Fetch is earlier than 0:0.26-130.el6_4" test_ref="oval:org.mitre.oval:tst:90559"/>
            <criterion comment="perl-Module-CoreList is earlier than 0:2.18-130.el6_4" test_ref="oval:org.mitre.oval:tst:90754"/>
            <criterion comment="perl-IO-Zlib is earlier than 1:1.09-130.el6_4" test_ref="oval:org.mitre.oval:tst:90096"/>
            <criterion comment="perl-Params-Check is earlier than 1:0.26-130.el6_4" test_ref="oval:org.mitre.oval:tst:90786"/>
            <criterion comment="perl-Compress-Zlib is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:90315"/>
            <criterion comment="perl is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:90538"/>
            <criterion comment="perl-Module-Load-Conditional is earlier than 0:0.30-130.el6_4" test_ref="oval:org.mitre.oval:tst:91057"/>
            <criterion comment="perl-Digest-SHA is earlier than 1:5.47-130.el6_4" test_ref="oval:org.mitre.oval:tst:90376"/>
            <criterion comment="perl-Locale-Maketext-Simple is earlier than 1:0.18-130.el6_4" test_ref="oval:org.mitre.oval:tst:90962"/>
            <criterion comment="perl-Time-Piece is earlier than 0:1.15-130.el6_4" test_ref="oval:org.mitre.oval:tst:90607"/>
            <criterion comment="perl-Archive-Tar is earlier than 0:1.58-130.el6_4" test_ref="oval:org.mitre.oval:tst:91071"/>
            <criterion comment="perl-devel is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:90817"/>
            <criterion comment="perl-Parse-CPAN-Meta is earlier than 1:1.40-130.el6_4" test_ref="oval:org.mitre.oval:tst:90961"/>
            <criterion comment="perl-ExtUtils-MakeMaker is earlier than 0:6.55-130.el6_4" test_ref="oval:org.mitre.oval:tst:90581"/>
            <criterion comment="perl-Module-Build is earlier than 1:0.3500-130.el6_4" test_ref="oval:org.mitre.oval:tst:90924"/>
            <criterion comment="perl-IPC-Cmd is earlier than 1:0.56-130.el6_4" test_ref="oval:org.mitre.oval:tst:90959"/>
            <criterion comment="perl-CPAN is earlier than 0:1.9402-130.el6_4" test_ref="oval:org.mitre.oval:tst:91090"/>
            <criterion comment="perl-Term-UI is earlier than 0:0.20-130.el6_4" test_ref="oval:org.mitre.oval:tst:91026"/>
            <criterion comment="perl-ExtUtils-Embed is earlier than 0:1.28-130.el6_4" test_ref="oval:org.mitre.oval:tst:90952"/>
            <criterion comment="perl-Object-Accessor is earlier than 1:0.34-130.el6_4" test_ref="oval:org.mitre.oval:tst:90229"/>
            <criterion comment="perl-Compress-Raw-Bzip2 is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:90544"/>
            <criterion comment="perl-Log-Message is earlier than 1:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:90712"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="perl-suidperl is earlier than 4:5.8.8-40.el5_9" test_ref="oval:org.mitre.oval:tst:91032"/>
            <criterion comment="perl is earlier than 4:5.8.8-40.el5_9" test_ref="oval:org.mitre.oval:tst:91080"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20987" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0189: ipa-client security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>ipa-client</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0189-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0189.html"/>
        <reference source="CESA" ref_id="CESA-2013:0189"/>
        <reference source="CVE" ref_id="CVE-2012-5484" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5484.html"/>
        <description>The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:17.476-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:51.490-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:01.555-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="ipa-client is earlier than 0:2.1.3-5.el5_9.2" test_ref="oval:org.mitre.oval:tst:90382"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20981" version="311" class="patch">
      <metadata>
        <title>RHSA-2013:0247: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0247-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0247.html"/>
        <reference source="CESA" ref_id="CESA-2013:0247"/>
        <reference source="CVE" ref_id="CVE-2013-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0424.html"/>
        <reference source="CVE" ref_id="CVE-2013-0425" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0425.html"/>
        <reference source="CVE" ref_id="CVE-2013-0426" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0426.html"/>
        <reference source="CVE" ref_id="CVE-2013-0427" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0427.html"/>
        <reference source="CVE" ref_id="CVE-2013-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0428.html"/>
        <reference source="CVE" ref_id="CVE-2013-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0429.html"/>
        <reference source="CVE" ref_id="CVE-2013-0431" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0431.html"/>
        <reference source="CVE" ref_id="CVE-2013-0432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0432.html"/>
        <reference source="CVE" ref_id="CVE-2013-0433" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0433.html"/>
        <reference source="CVE" ref_id="CVE-2013-0434" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0434.html"/>
        <reference source="CVE" ref_id="CVE-2013-0435" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0435.html"/>
        <reference source="CVE" ref_id="CVE-2013-0440" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0440.html"/>
        <reference source="CVE" ref_id="CVE-2013-0441" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0441.html"/>
        <reference source="CVE" ref_id="CVE-2013-0442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0442.html"/>
        <reference source="CVE" ref_id="CVE-2013-0443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0443.html"/>
        <reference source="CVE" ref_id="CVE-2013-0444" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0444.html"/>
        <reference source="CVE" ref_id="CVE-2013-0445" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0445.html"/>
        <reference source="CVE" ref_id="CVE-2013-0450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0450.html"/>
        <reference source="CVE" ref_id="CVE-2013-1475" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1475.html"/>
        <reference source="CVE" ref_id="CVE-2013-1476" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1476.html"/>
        <reference source="CVE" ref_id="CVE-2013-1478" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1478.html"/>
        <reference source="CVE" ref_id="CVE-2013-1480" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1480.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient validation of raster parameters" in awt_parseImage.c, which triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:46.461-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:50.461-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:00.680-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:89907"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:90463"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:90394"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:90351"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:90318"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:90195"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:90371"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:90410"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:90439"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:90462"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20976" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0324: libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0324-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0324.html"/>
        <reference source="CESA" ref_id="CESA-2012:0324"/>
        <reference source="CVE" ref_id="CVE-2012-0841" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0841.html"/>
        <description>libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:25.669-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:24.724-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:41.189-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.el5_8.2" test_ref="oval:org.mitre.oval:tst:92439"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.el5_8.2" test_ref="oval:org.mitre.oval:tst:93061"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.el5_8.2" test_ref="oval:org.mitre.oval:tst:92745"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:93069"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:93014"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:93032"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:92829"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20972" version="94" class="patch">
      <metadata>
        <title>RHSA-2012:0469: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0469-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0469.html"/>
        <reference source="CVE" ref_id="CVE-2011-4370" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4370.html"/>
        <reference source="CVE" ref_id="CVE-2011-4371" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4371.html"/>
        <reference source="CVE" ref_id="CVE-2011-4372" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4372.html"/>
        <reference source="CVE" ref_id="CVE-2011-4373" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4373.html"/>
        <reference source="CVE" ref_id="CVE-2012-0774" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0774.html"/>
        <reference source="CVE" ref_id="CVE-2012-0775" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0775.html"/>
        <reference source="CVE" ref_id="CVE-2012-0777" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0777.html"/>
        <description>The JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 on Mac OS X and Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:46.262-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:24.354-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:40.728-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.5.1-1.el5" test_ref="oval:org.mitre.oval:tst:92957"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.1-1.el5" test_ref="oval:org.mitre.oval:tst:93105"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.5.1-1.el6_2" test_ref="oval:org.mitre.oval:tst:92952"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.1-1.el6_2" test_ref="oval:org.mitre.oval:tst:93278"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20966" version="59" class="patch">
      <metadata>
        <title>RHSA-2013:0640: tomcat5 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>tomcat5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0640-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0640.html"/>
        <reference source="CESA" ref_id="CESA-2013:0640"/>
        <reference source="CVE" ref_id="CVE-2012-3546" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3546.html"/>
        <reference source="CVE" ref_id="CVE-2012-5885" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5885.html"/>
        <reference source="CVE" ref_id="CVE-2012-5886" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5886.html"/>
        <reference source="CVE" ref_id="CVE-2012-5887" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5887.html"/>
        <description>The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:33.978-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:48.570-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:59.075-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:90710"/>
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:90560"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:90610"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:90936"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:90526"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:90756"/>
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:91013"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:90515"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:90829"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:90900"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:90135"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20962" version="121" class="patch">
      <metadata>
        <title>RHSA-2011:0364: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0364-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0364.html"/>
        <reference source="CVE" ref_id="CVE-2010-4447" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4447.html"/>
        <reference source="CVE" ref_id="CVE-2010-4448" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4448.html"/>
        <reference source="CVE" ref_id="CVE-2010-4450" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4450.html"/>
        <reference source="CVE" ref_id="CVE-2010-4454" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4454.html"/>
        <reference source="CVE" ref_id="CVE-2010-4462" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4462.html"/>
        <reference source="CVE" ref_id="CVE-2010-4465" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4465.html"/>
        <reference source="CVE" ref_id="CVE-2010-4466" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4466.html"/>
        <reference source="CVE" ref_id="CVE-2010-4468" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4468.html"/>
        <reference source="CVE" ref_id="CVE-2010-4471" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4471.html"/>
        <reference source="CVE" ref_id="CVE-2010-4473" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4473.html"/>
        <reference source="CVE" ref_id="CVE-2010-4475" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4475.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:20.030-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:23.923-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:40.335-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97441"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:96650"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97649"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97280"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97536"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97409"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97595"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97394"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:96679"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:96667"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97335"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97581"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97667"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97546"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97609"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20961" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0313: samba security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0313-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0313.html"/>
        <reference source="CVE" ref_id="CVE-2010-0926" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0926.html"/>
        <description>The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in smbclient to create a symlink containing .. (dot dot) sequences, related to the combination of the unix extensions and wide links options.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:09.761-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:23.830-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:40.221-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libsmbclient is earlier than 0:3.0.33-3.37.el5" test_ref="oval:org.mitre.oval:tst:92997"/>
          <criterion comment="samba is earlier than 0:3.0.33-3.37.el5" test_ref="oval:org.mitre.oval:tst:92850"/>
          <criterion comment="samba-swat is earlier than 0:3.0.33-3.37.el5" test_ref="oval:org.mitre.oval:tst:92577"/>
          <criterion comment="samba-client is earlier than 0:3.0.33-3.37.el5" test_ref="oval:org.mitre.oval:tst:92888"/>
          <criterion comment="samba-common is earlier than 0:3.0.33-3.37.el5" test_ref="oval:org.mitre.oval:tst:92614"/>
          <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.37.el5" test_ref="oval:org.mitre.oval:tst:92668"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20959" version="5" class="patch">
      <metadata>
        <title>RHSA-2013:0128: conga security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>conga</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0128-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0128.html"/>
        <reference source="CESA" ref_id="CESA-2013:0128"/>
        <reference source="CVE" ref_id="CVE-2012-3359" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3359.html"/>
        <description>Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie.  NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:24.363-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:48.377-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:58.942-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="ricci is earlier than 0:0.12.2-64.el5" test_ref="oval:org.mitre.oval:tst:90205"/>
            <criterion comment="luci is earlier than 0:0.12.2-64.el5" test_ref="oval:org.mitre.oval:tst:90285"/>
            <criterion comment="conga is earlier than 0:0.12.2-64.el5" test_ref="oval:org.mitre.oval:tst:90056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="ricci is earlier than 0:0.12.2-64.el5.centos" test_ref="oval:org.mitre.oval:tst:92166"/>
            <criterion comment="luci is earlier than 0:0.12.2-64.el5.centos" test_ref="oval:org.mitre.oval:tst:91859"/>
            <criterion comment="conga is earlier than 0:0.12.2-64.el5.centos" test_ref="oval:org.mitre.oval:tst:92127"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20957" version="107" class="patch">
      <metadata>
        <title>RHSA-2012:0127: mysql security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0127-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0127.html"/>
        <reference source="CESA" ref_id="CESA-2012:0127"/>
        <reference source="CVE" ref_id="CVE-2010-1849" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1849.html"/>
        <reference source="CVE" ref_id="CVE-2012-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0075.html"/>
        <reference source="CVE" ref_id="CVE-2012-0087" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0087.html"/>
        <reference source="CVE" ref_id="CVE-2012-0101" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0101.html"/>
        <reference source="CVE" ref_id="CVE-2012-0102" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0102.html"/>
        <reference source="CVE" ref_id="CVE-2012-0114" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0114.html"/>
        <reference source="CVE" ref_id="CVE-2012-0484" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0484.html"/>
        <reference source="CVE" ref_id="CVE-2012-0490" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0490.html"/>
        <description>Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x, 5.1.x, and 5.5.x allows remote authenticated users to affect availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:05.822-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:23.528-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:39.914-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mysql-server is earlier than 0:5.0.95-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:92983"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.95-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:92880"/>
          <criterion comment="mysql-test is earlier than 0:5.0.95-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:92819"/>
          <criterion comment="mysql is earlier than 0:5.0.95-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:92913"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.95-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:93000"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20953" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0241: xen security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0241-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0241.html"/>
        <reference source="CESA" ref_id="CESA-2013:0241"/>
        <reference source="CVE" ref_id="CVE-2012-4544" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4544.html"/>
        <description>The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:30.292-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:46.735-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:57.183-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="xen-devel is earlier than 0:3.0.3-142.el5_9.1" test_ref="oval:org.mitre.oval:tst:90503"/>
          <criterion comment="xen-libs is earlier than 0:3.0.3-142.el5_9.1" test_ref="oval:org.mitre.oval:tst:90469"/>
          <criterion comment="xen is earlier than 0:3.0.3-142.el5_9.1" test_ref="oval:org.mitre.oval:tst:90239"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20952" version="68" class="patch">
      <metadata>
        <title>RHSA-2012:1181: gimp security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gimp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1181-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1181.html"/>
        <reference source="CESA" ref_id="CESA-2012:1181"/>
        <reference source="CVE" ref_id="CVE-2009-3909" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3909.html"/>
        <reference source="CVE" ref_id="CVE-2011-2896" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2896.html"/>
        <reference source="CVE" ref_id="CVE-2012-3402" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3402.html"/>
        <reference source="CVE" ref_id="CVE-2012-3403" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3403.html"/>
        <reference source="CVE" ref_id="CVE-2012-3481" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3481.html"/>
        <description>Integer overflow in the ReadImage function in plug-ins/common/file-gif-load.c in the GIF image format plug-in in GIMP 2.8.x and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted height and len properties in a GIF image file, which triggers a heap-based buffer overflow.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:16.760-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:23.210-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:39.669-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="gimp-libs is earlier than 2:2.2.13-2.0.7.el5_8.5" test_ref="oval:org.mitre.oval:tst:94432"/>
          <criterion comment="gimp-devel is earlier than 2:2.2.13-2.0.7.el5_8.5" test_ref="oval:org.mitre.oval:tst:94309"/>
          <criterion comment="gimp is earlier than 2:2.2.13-2.0.7.el5_8.5" test_ref="oval:org.mitre.oval:tst:94425"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20949" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0129: ruby security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0129-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0129.html"/>
        <reference source="CESA" ref_id="CESA-2013:0129"/>
        <reference source="CVE" ref_id="CVE-2012-4481" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4481.html"/>
        <reference source="CVE" ref_id="CVE-2012-4522" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4522.html"/>
        <description>The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to create files in unexpected locations or with unexpected names via a NUL byte in a file path.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:43.282-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:46.306-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:57.052-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="ruby-tcltk is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:90100"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:89987"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:90119"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:90045"/>
          <criterion comment="ruby-mode is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:90225"/>
          <criterion comment="ruby is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:89901"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:90178"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:90344"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:89953"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20942" version="47" class="patch">
      <metadata>
        <title>RHSA-2013:1035: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1035-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1035.html"/>
        <reference source="CVE" ref_id="CVE-2013-3344" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3344.html"/>
        <reference source="CVE" ref_id="CVE-2013-3345" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3345.html"/>
        <reference source="CVE" ref_id="CVE-2013-3347" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3347.html"/>
        <description>Integer overflow in Adobe Flash Player before 11.7.700.232 and 11.8.x before 11.8.800.94 on Windows and Mac OS X, before 11.2.202.297 on Linux, before 11.1.111.64 on Android 2.x and 3.x, and before 11.1.115.69 on Android 4.x allows attackers to execute arbitrary code via PCM data that is not properly handled during resampling.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:43.079-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:44.861-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:55.492-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20942 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:13.742-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:23.543-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.297-1.el5" test_ref="oval:org.mitre.oval:tst:137761"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.297-1.el6" test_ref="oval:org.mitre.oval:tst:91097"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20941" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0309: sudo security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0309-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0309.html"/>
        <reference source="CVE" ref_id="CVE-2011-0010" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0010.html"/>
        <description>check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:10.388-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:22.950-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:39.189-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="sudo is earlier than 0:1.7.2p1-13.el5" test_ref="oval:org.mitre.oval:tst:93005"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20940" version="224" class="patch">
      <metadata>
        <title>RHSA-2012:0034: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0034-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0034.html"/>
        <reference source="CVE" ref_id="CVE-2011-3389" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3389.html"/>
        <reference source="CVE" ref_id="CVE-2011-3516" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3516.html"/>
        <reference source="CVE" ref_id="CVE-2011-3521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3521.html"/>
        <reference source="CVE" ref_id="CVE-2011-3544" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3544.html"/>
        <reference source="CVE" ref_id="CVE-2011-3545" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3545.html"/>
        <reference source="CVE" ref_id="CVE-2011-3546" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3546.html"/>
        <reference source="CVE" ref_id="CVE-2011-3547" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3547.html"/>
        <reference source="CVE" ref_id="CVE-2011-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3548.html"/>
        <reference source="CVE" ref_id="CVE-2011-3549" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3549.html"/>
        <reference source="CVE" ref_id="CVE-2011-3550" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3550.html"/>
        <reference source="CVE" ref_id="CVE-2011-3551" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3551.html"/>
        <reference source="CVE" ref_id="CVE-2011-3552" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3552.html"/>
        <reference source="CVE" ref_id="CVE-2011-3553" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3553.html"/>
        <reference source="CVE" ref_id="CVE-2011-3554" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3554.html"/>
        <reference source="CVE" ref_id="CVE-2011-3556" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3556.html"/>
        <reference source="CVE" ref_id="CVE-2011-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3557.html"/>
        <reference source="CVE" ref_id="CVE-2011-3560" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3560.html"/>
        <reference source="CVE" ref_id="CVE-2011-3561" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3561.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JavaFX 2.0 allows remote attackers to affect confidentiality via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:51.215-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:22.297-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:38.612-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:92500"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:92625"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:92358"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:92727"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:92428"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:92212"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:92489"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:92626"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:92386"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:92465"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:92090"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:92437"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:92341"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:92764"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:92633"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20938" version="42" class="patch">
      <metadata>
        <title>RHSA-2012:0451: rpm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>rpm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0451-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0451.html"/>
        <reference source="CESA" ref_id="CESA-2012:0451"/>
        <reference source="CVE" ref_id="CVE-2012-0060" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0060.html"/>
        <reference source="CVE" ref_id="CVE-2012-0061" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0061.html"/>
        <reference source="CVE" ref_id="CVE-2012-0815" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0815.html"/>
        <description>The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:15.195-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:22.084-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:38.262-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="rpm is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:92975"/>
            <criterion comment="rpm-python is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:93125"/>
            <criterion comment="rpm-libs is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:93265"/>
            <criterion comment="rpm-build is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:92801"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:92865"/>
            <criterion comment="popt is earlier than 0:1.10.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:93340"/>
            <criterion comment="rpm-devel is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:93007"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="rpm-cron is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:93240"/>
            <criterion comment="rpm is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:93010"/>
            <criterion comment="rpm-libs is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:93066"/>
            <criterion comment="rpm-python is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:93306"/>
            <criterion comment="rpm-build is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:92355"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:93159"/>
            <criterion comment="rpm-devel is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:93234"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20935" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0124: net-snmp security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>net-snmp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0124-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0124.html"/>
        <reference source="CESA" ref_id="CESA-2013:0124"/>
        <reference source="CVE" ref_id="CVE-2012-2141" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2141.html"/>
        <description>Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend.c in Net-SNMP 5.7.1 allows remote authenticated users to cause a denial of service (out-of-bounds read and snmpd crash) via an SNMP GET request for an entry not in the extension table.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:13.708-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:44.720-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:55.353-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="net-snmp-utils is earlier than 1:5.3.2.2-20.el5" test_ref="oval:org.mitre.oval:tst:90158"/>
          <criterion comment="net-snmp-devel is earlier than 1:5.3.2.2-20.el5" test_ref="oval:org.mitre.oval:tst:89543"/>
          <criterion comment="net-snmp-perl is earlier than 1:5.3.2.2-20.el5" test_ref="oval:org.mitre.oval:tst:89967"/>
          <criterion comment="net-snmp-libs is earlier than 1:5.3.2.2-20.el5" test_ref="oval:org.mitre.oval:tst:90060"/>
          <criterion comment="net-snmp is earlier than 1:5.3.2.2-20.el5" test_ref="oval:org.mitre.oval:tst:89996"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20933" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0627: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0627-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0627.html"/>
        <reference source="CESA" ref_id="CESA-2013:0627"/>
        <reference source="CVE" ref_id="CVE-2013-0787" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0787.html"/>
        <description>Use-after-free vulnerability in the nsEditor::IsPreformatted function in editor/libeditor/base/nsEditor.cpp in Mozilla Firefox before 19.0.2, Firefox ESR 17.x before 17.0.4, Thunderbird before 17.0.4, Thunderbird ESR 17.x before 17.0.4, and SeaMonkey before 2.16.1 allows remote attackers to execute arbitrary code via vectors involving an execCommand call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:12.255-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:44.589-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:55.219-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.3-2.el6_4" test_ref="oval:org.mitre.oval:tst:90753"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.3-2.el6.centos" test_ref="oval:org.mitre.oval:tst:91855"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-2.el5_9" test_ref="oval:org.mitre.oval:tst:90002"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-2.el5.centos" test_ref="oval:org.mitre.oval:tst:91615"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20931" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1049: php security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1049-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1049.html"/>
        <reference source="CESA" ref_id="CESA-2013:1049"/>
        <reference source="CVE" ref_id="CVE-2013-4113" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4113.html"/>
        <description>ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:58.138-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:44.344-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:54.961-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php-embedded is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:90523"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91273"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91428"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91400"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91430"/>
            <criterion comment="php is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91289"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91353"/>
            <criterion comment="php-process is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91426"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91205"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:90530"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:90938"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91361"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91384"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:90630"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91056"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91264"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91417"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91520"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91419"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91404"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91327"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91401"/>
            <criterion comment="php-common is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:90724"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91299"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:90667"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91087"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91276"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php-xml is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91453"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91522"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:90570"/>
            <criterion comment="php is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91326"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91510"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91568"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:90704"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91468"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91515"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91305"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91391"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:90823"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91308"/>
            <criterion comment="php-common is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91182"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91322"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91208"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91101"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91423"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91203"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20926" version="33" class="patch">
      <metadata>
        <title>RHSA-2013:0243: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0243-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0243.html"/>
        <reference source="CVE" ref_id="CVE-2013-0633" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0633.html"/>
        <reference source="CVE" ref_id="CVE-2013-0634" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0634.html"/>
        <description>Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on Linux, before 11.1.111.32 on Android 2.x and 3.x, and before 11.1.115.37 on Android 4.x allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:28.933-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:43.819-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:54.282-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20926 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:05.823-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:22.936-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.262-1.el5" test_ref="oval:org.mitre.oval:tst:137704"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.262-1.el6" test_ref="oval:org.mitre.oval:tst:89863"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20919" version="61" class="patch">
      <metadata>
        <title>RHSA-2013:1256: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1256-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1256.html"/>
        <reference source="CVE" ref_id="CVE-2013-3361" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3361.html"/>
        <reference source="CVE" ref_id="CVE-2013-3362" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3362.html"/>
        <reference source="CVE" ref_id="CVE-2013-3363" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3363.html"/>
        <reference source="CVE" ref_id="CVE-2013-5324" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5324.html"/>
        <description>Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Android 4.x; Adobe AIR before 3.8.0.1430; and Adobe AIR SDK &amp; Compiler before 3.8.0.1430 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3361, CVE-2013-3362, and CVE-2013-3363.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:53.619-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:43.480-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:54.048-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20919 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:31.239-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:22.439-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.310-1.el5" test_ref="oval:org.mitre.oval:tst:137342"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.310-1.el6" test_ref="oval:org.mitre.oval:tst:91058"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20914" version="55" class="patch">
      <metadata>
        <title>RHSA-2012:0095: ghostscript security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>ghostscript</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0095-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0095.html"/>
        <reference source="CESA" ref_id="CESA-2012:0095"/>
        <reference source="CVE" ref_id="CVE-2009-3743" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3743.html"/>
        <reference source="CVE" ref_id="CVE-2010-2055" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2055.html"/>
        <reference source="CVE" ref_id="CVE-2010-4054" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4054.html"/>
        <reference source="CVE" ref_id="CVE-2010-4820" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4820.html"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:44.378-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:21.608-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:37.555-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:92780"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:93020"/>
            <criterion comment="ghostscript-doc is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:92734"/>
            <criterion comment="ghostscript is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:92766"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-6.el5_7.6" test_ref="oval:org.mitre.oval:tst:92620"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-6.el5_7.6" test_ref="oval:org.mitre.oval:tst:92999"/>
            <criterion comment="ghostscript is earlier than 0:8.70-6.el5_7.6" test_ref="oval:org.mitre.oval:tst:92891"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20911" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:0727: kvm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0727-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0727.html"/>
        <reference source="CESA" ref_id="CESA-2013:0727"/>
        <reference source="CVE" ref_id="CVE-2013-1796" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1796.html"/>
        <reference source="CVE" ref_id="CVE-2013-1797" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1797.html"/>
        <reference source="CVE" ref_id="CVE-2013-1798" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1798.html"/>
        <description>The ioapic_read_indirect function in virt/kvm/ioapic.c in the Linux kernel through 3.8.4 does not properly handle a certain combination of invalid IOAPIC_REG_SELECT and IOAPIC_REG_WINDOW operations, which allows guest OS users to obtain sensitive information from host OS memory or cause a denial of service (host OS OOPS) via a crafted application.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:53.612-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:43.159-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:53.717-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="kvm-tools is earlier than 0:83-262.el5_9.3" test_ref="oval:org.mitre.oval:tst:90609"/>
            <criterion comment="kmod-kvm is earlier than 0:83-262.el5_9.3" test_ref="oval:org.mitre.oval:tst:90816"/>
            <criterion comment="kmod-kvm-debug is earlier than 0:83-262.el5_9.3" test_ref="oval:org.mitre.oval:tst:91079"/>
            <criterion comment="kvm-qemu-img is earlier than 0:83-262.el5_9.3" test_ref="oval:org.mitre.oval:tst:91025"/>
            <criterion comment="kvm is earlier than 0:83-262.el5_9.3" test_ref="oval:org.mitre.oval:tst:90856"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="kvm-tools is earlier than 0:83-262.el5.centos.3" test_ref="oval:org.mitre.oval:tst:92180"/>
            <criterion comment="kmod-kvm is earlier than 0:83-262.el5.centos.3" test_ref="oval:org.mitre.oval:tst:92022"/>
            <criterion comment="kmod-kvm-debug is earlier than 0:83-262.el5.centos.3" test_ref="oval:org.mitre.oval:tst:91871"/>
            <criterion comment="kvm-qemu-img is earlier than 0:83-262.el5.centos.3" test_ref="oval:org.mitre.oval:tst:92282"/>
            <criterion comment="kvm is earlier than 0:83-262.el5.centos.3" test_ref="oval:org.mitre.oval:tst:92258"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20910" version="6" class="patch">
      <metadata>
        <title>RHSA-2013:0941: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0941-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0941.html"/>
        <reference source="CVE" ref_id="CVE-2013-3343" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3343.html"/>
        <description>Adobe Flash Player before 10.3.183.90 and 11.x before 11.7.700.224 on Windows, before 10.3.183.90 and 11.x before 11.7.700.225 on Mac OS X, before 10.3.183.90 and 11.x before 11.2.202.291 on Linux, before 11.1.111.59 on Android 2.x and 3.x, and before 11.1.115.63 on Android 4.x; Adobe AIR before 3.7.0.2090 on Windows and Android and before 3.7.0.2100 on Mac OS X; and Adobe AIR SDK &amp; Compiler before 3.7.0.2090 on Windows and before 3.7.0.2100 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:27.922-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:43.040-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:53.619-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20910 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:34.240-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:22.117-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.291-1.el5" test_ref="oval:org.mitre.oval:tst:137675"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.291-1.el6" test_ref="oval:org.mitre.oval:tst:91379"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20907" version="115" class="patch">
      <metadata>
        <title>RHSA-2013:1269: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1269-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1269.html"/>
        <reference source="CESA" ref_id="CESA-2013:1269"/>
        <reference source="CVE" ref_id="CVE-2013-1718" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1718.html"/>
        <reference source="CVE" ref_id="CVE-2013-1722" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1722.html"/>
        <reference source="CVE" ref_id="CVE-2013-1725" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1725.html"/>
        <reference source="CVE" ref_id="CVE-2013-1730" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1730.html"/>
        <reference source="CVE" ref_id="CVE-2013-1732" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1732.html"/>
        <reference source="CVE" ref_id="CVE-2013-1735" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1735.html"/>
        <reference source="CVE" ref_id="CVE-2013-1736" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1736.html"/>
        <reference source="CVE" ref_id="CVE-2013-1737" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1737.html"/>
        <description>Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the "this" object during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expando object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:37.718-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:42.369-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:52.958-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:91569"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.9-1.el6.centos" test_ref="oval:org.mitre.oval:tst:91610"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:91549"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:17.0.9-1.el5.centos" test_ref="oval:org.mitre.oval:tst:92032"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20905" version="59" class="patch">
      <metadata>
        <title>RHSA-2013:0737: subversion security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0737-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0737.html"/>
        <reference source="CESA" ref_id="CESA-2013:0737"/>
        <reference source="CVE" ref_id="CVE-2013-1845" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1845.html"/>
        <reference source="CVE" ref_id="CVE-2013-1846" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1846.html"/>
        <reference source="CVE" ref_id="CVE-2013-1847" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1847.html"/>
        <reference source="CVE" ref_id="CVE-2013-1849" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1849.html"/>
        <description>The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:20.702-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:42.114-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:52.731-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:90885"/>
            <criterion comment="subversion-kde is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:91117"/>
            <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:90860"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:90929"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:91148"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:91136"/>
            <criterion comment="subversion-gnome is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:90861"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:91126"/>
            <criterion comment="subversion is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:90671"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:90969"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:91040"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:90979"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:91130"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:91166"/>
            <criterion comment="subversion is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:90824"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20894" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0581: libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0581-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0581.html"/>
        <reference source="CESA" ref_id="CESA-2013:0581"/>
        <reference source="CVE" ref_id="CVE-2013-0338" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0338.html"/>
        <description>libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:11.707-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:40.574-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:51.272-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:90765"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:90683"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:90193"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:89794"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.21.el5_9.1" test_ref="oval:org.mitre.oval:tst:90688"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.21.el5_9.1" test_ref="oval:org.mitre.oval:tst:90256"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.21.el5_9.1" test_ref="oval:org.mitre.oval:tst:90374"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20890" version="185" class="patch">
      <metadata>
        <title>RHSA-2013:0125: wireshark security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0125-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0125.html"/>
        <reference source="CESA" ref_id="CESA-2013:0125"/>
        <reference source="CVE" ref_id="CVE-2011-1958" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1958.html"/>
        <reference source="CVE" ref_id="CVE-2011-1959" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1959.html"/>
        <reference source="CVE" ref_id="CVE-2011-2175" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2175.html"/>
        <reference source="CVE" ref_id="CVE-2011-2698" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2698.html"/>
        <reference source="CVE" ref_id="CVE-2011-4102" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4102.html"/>
        <reference source="CVE" ref_id="CVE-2012-0041" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0041.html"/>
        <reference source="CVE" ref_id="CVE-2012-0042" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0042.html"/>
        <reference source="CVE" ref_id="CVE-2012-0066" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0066.html"/>
        <reference source="CVE" ref_id="CVE-2012-0067" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0067.html"/>
        <reference source="CVE" ref_id="CVE-2012-4285" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4285.html"/>
        <reference source="CVE" ref_id="CVE-2012-4289" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4289.html"/>
        <reference source="CVE" ref_id="CVE-2012-4290" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4290.html"/>
        <reference source="CVE" ref_id="CVE-2012-4291" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4291.html"/>
        <description>The CIP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:26.491-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:40.098-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:50.690-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="wireshark-gnome is earlier than 0:1.0.15-5.el5" test_ref="oval:org.mitre.oval:tst:90263"/>
          <criterion comment="wireshark is earlier than 0:1.0.15-5.el5" test_ref="oval:org.mitre.oval:tst:89890"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20888" version="101" class="patch">
      <metadata>
        <title>RHSA-2013:0747: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0747-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0747.html"/>
        <reference source="CESA" ref_id="CESA-2013:0747"/>
        <reference source="CVE" ref_id="CVE-2012-6537" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6537.html"/>
        <reference source="CVE" ref_id="CVE-2012-6542" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6542.html"/>
        <reference source="CVE" ref_id="CVE-2012-6546" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6546.html"/>
        <reference source="CVE" ref_id="CVE-2012-6547" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6547.html"/>
        <reference source="CVE" ref_id="CVE-2013-0216" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0216.html"/>
        <reference source="CVE" ref_id="CVE-2013-0231" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0231.html"/>
        <reference source="CVE" ref_id="CVE-2013-1826" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1826.html"/>
        <description>The xfrm_state_netlink function in net/xfrm/xfrm_user.c in the Linux kernel before 3.5.7 does not properly handle error conditions in dump_one_state function calls, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:50.233-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:39.764-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:50.334-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:90987"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:91107"/>
          <criterion comment="kernel is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:91176"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:91139"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:91181"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:91179"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:91163"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:91232"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:90955"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:91250"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:90705"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:90884"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20884" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0594: kernel security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0594-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0594.html"/>
        <reference source="CESA" ref_id="CESA-2013:0594"/>
        <reference source="CVE" ref_id="CVE-2012-3400" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3400.html"/>
        <description>Heap-based buffer overflow in the udf_load_logicalvol function in fs/udf/super.c in the Linux kernel before 3.4.5 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted UDF filesystem.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:59.157-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:39.546-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:50.025-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:90338"/>
          <criterion comment="kernel is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:90695"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:90877"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:90629"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:90555"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:90791"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:90897"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:90770"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:89917"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:90627"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:90261"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:90875"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20868" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0092: php53 security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>php53</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0092-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0092.html"/>
        <reference source="CESA" ref_id="CESA-2012:0092"/>
        <reference source="CVE" ref_id="CVE-2012-0830" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0830.html"/>
        <description>The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:25.041-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:20.985-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:36.542-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:92525"/>
          <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:92675"/>
          <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:92861"/>
          <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:92708"/>
          <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:92699"/>
          <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:92409"/>
          <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:92682"/>
          <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:91910"/>
          <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:91872"/>
          <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:92840"/>
          <criterion comment="php53 is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:92808"/>
          <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:92609"/>
          <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:92665"/>
          <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:92779"/>
          <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:92786"/>
          <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:92043"/>
          <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:92527"/>
          <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:92334"/>
          <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:92851"/>
          <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:92542"/>
          <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:92700"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20865" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0011: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0011-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0011.html"/>
        <reference source="CVE" ref_id="CVE-2011-2462" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2462.html"/>
        <reference source="CVE" ref_id="CVE-2011-4369" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4369.html"/>
        <description>Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6 on Mac OS X, Adobe Reader and Acrobat 10.x through 10.1.1 on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:36.399-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:20.809-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:36.329-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:92512"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:92798"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.4.7-1.el6" test_ref="oval:org.mitre.oval:tst:92254"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.7-1.el6" test_ref="oval:org.mitre.oval:tst:92782"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20855" version="171" class="patch">
      <metadata>
        <title>RHSA-2013:0144: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0144-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0144.html"/>
        <reference source="CESA" ref_id="CESA-2013:0144"/>
        <reference source="CVE" ref_id="CVE-2013-0744" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0744.html"/>
        <reference source="CVE" ref_id="CVE-2013-0746" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0746.html"/>
        <reference source="CVE" ref_id="CVE-2013-0748" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0748.html"/>
        <reference source="CVE" ref_id="CVE-2013-0750" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0750.html"/>
        <reference source="CVE" ref_id="CVE-2013-0753" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0753.html"/>
        <reference source="CVE" ref_id="CVE-2013-0754" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0754.html"/>
        <reference source="CVE" ref_id="CVE-2013-0758" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0758.html"/>
        <reference source="CVE" ref_id="CVE-2013-0759" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0759.html"/>
        <reference source="CVE" ref_id="CVE-2013-0762" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0762.html"/>
        <reference source="CVE" ref_id="CVE-2013-0766" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0766.html"/>
        <reference source="CVE" ref_id="CVE-2013-0767" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0767.html"/>
        <reference source="CVE" ref_id="CVE-2013-0769" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0769.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:16.053-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:37.753-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:47.485-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.12-1.el6_3" test_ref="oval:org.mitre.oval:tst:90361"/>
            <criterion comment="xulrunner is earlier than 0:10.0.12-1.el6_3" test_ref="oval:org.mitre.oval:tst:90186"/>
            <criterion comment="firefox is earlier than 0:10.0.12-1.el6_3" test_ref="oval:org.mitre.oval:tst:90260"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.12-1.el6.centos" test_ref="oval:org.mitre.oval:tst:91449"/>
            <criterion comment="xulrunner is earlier than 0:10.0.12-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92112"/>
            <criterion comment="firefox is earlier than 0:10.0.12-1.el6.centos" test_ref="oval:org.mitre.oval:tst:91642"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.12-1.el5_9" test_ref="oval:org.mitre.oval:tst:90138"/>
            <criterion comment="xulrunner is earlier than 0:10.0.12-1.el5_9" test_ref="oval:org.mitre.oval:tst:90031"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:10.0.12-1.el5.centos" test_ref="oval:org.mitre.oval:tst:91994"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:10.0.12-1.el5_9" test_ref="oval:org.mitre.oval:tst:89474"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20851" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0690: bind97 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0690-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0690.html"/>
        <reference source="CESA" ref_id="CESA-2013:0690"/>
        <reference source="CVE" ref_id="CVE-2013-2266" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2266.html"/>
        <description>libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms allows remote attackers to cause a denial of service (memory consumption) via a crafted regular expression, as demonstrated by a memory-exhaustion attack against a machine running a named process.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:51.120-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:37.395-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:47.250-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="bind97-utils is earlier than 32:9.7.0-17.P2.el5_9.1" test_ref="oval:org.mitre.oval:tst:91027"/>
          <criterion comment="bind97 is earlier than 32:9.7.0-17.P2.el5_9.1" test_ref="oval:org.mitre.oval:tst:90851"/>
          <criterion comment="bind97-libs is earlier than 32:9.7.0-17.P2.el5_9.1" test_ref="oval:org.mitre.oval:tst:90675"/>
          <criterion comment="bind97-chroot is earlier than 32:9.7.0-17.P2.el5_9.1" test_ref="oval:org.mitre.oval:tst:91132"/>
          <criterion comment="bind97-devel is earlier than 32:9.7.0-17.P2.el5_9.1" test_ref="oval:org.mitre.oval:tst:90618"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20848" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1480: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1480-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1480.html"/>
        <reference source="CESA" ref_id="CESA-2013:1480"/>
        <reference source="CVE" ref_id="CVE-2013-5599" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5599.html"/>
        <description>Use-after-free vulnerability in the nsIPresShell::GetPresContext function in the PresShell (aka presentation shell) implementation in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via vectors involving a CANVAS element, a mozTextStyle attribute, and an onresize event.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:43.231-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:36.852-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:46.415-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:91552"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92285"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:90990"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.el5.centos" test_ref="oval:org.mitre.oval:tst:91844"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20833" version="59" class="patch">
      <metadata>
        <title>RHSA-2013:1458: gnupg security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gnupg</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1458-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1458.html"/>
        <reference source="CESA" ref_id="CESA-2013:1458"/>
        <reference source="CVE" ref_id="CVE-2012-6085" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6085.html"/>
        <reference source="CVE" ref_id="CVE-2013-4242" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4242.html"/>
        <reference source="CVE" ref_id="CVE-2013-4351" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4351.html"/>
        <reference source="CVE" ref_id="CVE-2013-4402" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4402.html"/>
        <description>The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recursion) via a crafted OpenPGP message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:41.615-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:35.642-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:43.821-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="gnupg is earlier than 0:1.4.5-18.el5_10" test_ref="oval:org.mitre.oval:tst:91016"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20827" version="143" class="patch">
      <metadata>
        <title>RHSA-2013:0982: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0982-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0982.html"/>
        <reference source="CESA" ref_id="CESA-2013:0982"/>
        <reference source="CVE" ref_id="CVE-2013-1682" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1682.html"/>
        <reference source="CVE" ref_id="CVE-2013-1684" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1684.html"/>
        <reference source="CVE" ref_id="CVE-2013-1685" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1685.html"/>
        <reference source="CVE" ref_id="CVE-2013-1686" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1686.html"/>
        <reference source="CVE" ref_id="CVE-2013-1687" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1687.html"/>
        <reference source="CVE" ref_id="CVE-2013-1690" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1690.html"/>
        <reference source="CVE" ref_id="CVE-2013-1692" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1692.html"/>
        <reference source="CVE" ref_id="CVE-2013-1693" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1693.html"/>
        <reference source="CVE" ref_id="CVE-2013-1694" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1694.html"/>
        <reference source="CVE" ref_id="CVE-2013-1697" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1697.html"/>
        <description>The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly restrict use of DefaultValue for method calls, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that triggers use of a user-defined (1) toString or (2) valueOf method.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:18.059-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:34.953-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:43.242-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:91506"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.7-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92088"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:91503"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:17.0.7-1.el5.centos" test_ref="oval:org.mitre.oval:tst:92131"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20824" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0134: freeradius2 security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>freeradius2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0134-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0134.html"/>
        <reference source="CESA" ref_id="CESA-2013:0134"/>
        <reference source="CVE" ref_id="CVE-2011-4966" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4966.html"/>
        <description>modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenticated users to authenticate using an expired password.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:48.034-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:34.824-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:42.975-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="freeradius2 is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:90057"/>
          <criterion comment="freeradius2-ldap is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:90299"/>
          <criterion comment="freeradius2-unixODBC is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:89975"/>
          <criterion comment="freeradius2-perl is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:90033"/>
          <criterion comment="freeradius2-python is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:90181"/>
          <criterion comment="freeradius2-utils is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:90159"/>
          <criterion comment="freeradius2-postgresql is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:90169"/>
          <criterion comment="freeradius2-mysql is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:90357"/>
          <criterion comment="freeradius2-krb5 is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:90129"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20823" version="42" class="patch">
      <metadata>
        <title>RHSA-2012:1413: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1413-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1413.html"/>
        <reference source="CESA" ref_id="CESA-2012:1413"/>
        <reference source="CVE" ref_id="CVE-2012-4194" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4194.html"/>
        <reference source="CVE" ref_id="CVE-2012-4195" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4195.html"/>
        <reference source="CVE" ref_id="CVE-2012-4196" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4196.html"/>
        <description>Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:00.926-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:20.137-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:35.485-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:93889"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.10-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94895"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:94753"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.10-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94808"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20822" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0165: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0165-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0165.html"/>
        <reference source="CESA" ref_id="CESA-2013:0165"/>
        <reference source="CVE" ref_id="CVE-2012-3174" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3174.html"/>
        <reference source="CVE" ref_id="CVE-2013-0422" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0422.html"/>
        <description>Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a private MBeanInstantiator object, then retrieving arbitrary Class references using the findClass method, and (2) using the Reflection API with recursion in a way that bypasses a security check by the java.lang.invoke.MethodHandles.Lookup.checkSecurityManager method due to the inability of the sun.reflect.Reflection.getCallerClass method to skip frames related to the new reflection API, as exploited in the wild in January 2013, as demonstrated by Blackhole and Nuclear Pack, and a different vulnerability than CVE-2012-4681 and CVE-2012-3174. NOTE: some parties have mapped the recursive Reflection API issue to CVE-2012-3174, but CVE-2012-3174 is for a different vulnerability whose details are not public as of 20130114.  CVE-2013-0422 covers both the JMX/MBean and Reflection API issues.  NOTE: it was originally reported that Java 6 was also vulnerable, but the reporter has retracted this claim, stating that Java 6 is not exploitable because the relevant code is called in a way that does not bypass security checks.  NOTE: as of 20130114, a reliable third party has claimed that the findClass/MBeanInstantiator vector was not fixed in Oracle Java 7 Update 11.  If there is still a vulnerable condition, then a separate CVE identifier might be created for the unfixed issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:01.467-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:34.680-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:42.599-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:90037"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:90309"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:90111"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:90341"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:90274"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:89635"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:90226"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:90353"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:90295"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:89394"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20811" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0533: samba and samba3x security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0533-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0533.html"/>
        <reference source="CESA" ref_id="CESA-2012:0533"/>
        <reference source="CVE" ref_id="CVE-2012-2111" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2111.html"/>
        <description>The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:11.148-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:19.813-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:35.220-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba3x-doc is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:93088"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:93296"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:93288"/>
            <criterion comment="samba3x is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:93338"/>
            <criterion comment="samba3x-client is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:93339"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:92936"/>
            <criterion comment="samba3x-swat is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:93290"/>
            <criterion comment="samba3x-common is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:93391"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba-client is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:92947"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:93091"/>
            <criterion comment="samba is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:92968"/>
            <criterion comment="samba-common is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:93188"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:93314"/>
            <criterion comment="samba-doc is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:93131"/>
            <criterion comment="samba-winbind is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:92423"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:92876"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:93260"/>
            <criterion comment="samba-swat is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:93280"/>
            <criterion comment="libsmbclient is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:93080"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:93144"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20807" version="353" class="patch">
      <metadata>
        <title>RHSA-2013:1014: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1014-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1014.html"/>
        <reference source="CESA" ref_id="CESA-2013:1014"/>
        <reference source="CVE" ref_id="CVE-2013-1500" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1500.html"/>
        <reference source="CVE" ref_id="CVE-2013-1571" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1571.html"/>
        <reference source="CVE" ref_id="CVE-2013-2407" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2407.html"/>
        <reference source="CVE" ref_id="CVE-2013-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2412.html"/>
        <reference source="CVE" ref_id="CVE-2013-2443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2443.html"/>
        <reference source="CVE" ref_id="CVE-2013-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2444.html"/>
        <reference source="CVE" ref_id="CVE-2013-2445" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2445.html"/>
        <reference source="CVE" ref_id="CVE-2013-2446" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2446.html"/>
        <reference source="CVE" ref_id="CVE-2013-2447" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2447.html"/>
        <reference source="CVE" ref_id="CVE-2013-2448" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2448.html"/>
        <reference source="CVE" ref_id="CVE-2013-2450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2450.html"/>
        <reference source="CVE" ref_id="CVE-2013-2452" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2452.html"/>
        <reference source="CVE" ref_id="CVE-2013-2453" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2453.html"/>
        <reference source="CVE" ref_id="CVE-2013-2455" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2455.html"/>
        <reference source="CVE" ref_id="CVE-2013-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2456.html"/>
        <reference source="CVE" ref_id="CVE-2013-2457" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2457.html"/>
        <reference source="CVE" ref_id="CVE-2013-2459" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2459.html"/>
        <reference source="CVE" ref_id="CVE-2013-2461" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2461.html"/>
        <reference source="CVE" ref_id="CVE-2013-2463" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2463.html"/>
        <reference source="CVE" ref_id="CVE-2013-2465" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2465.html"/>
        <reference source="CVE" ref_id="CVE-2013-2469" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2469.html"/>
        <reference source="CVE" ref_id="CVE-2013-2470" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2470.html"/>
        <reference source="CVE" ref_id="CVE-2013-2471" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2471.html"/>
        <reference source="CVE" ref_id="CVE-2013-2472" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2472.html"/>
        <reference source="CVE" ref_id="CVE-2013-2473" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2473.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect ByteBandedRaster size checks" in 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:18.992-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:33.264-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:40.526-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:90750"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:90758"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:91390"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:91354"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:90542"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:91120"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:91352"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:91144"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:91474"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:91008"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20806" version="61" class="patch">
      <metadata>
        <title>RHSA-2013:0643: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0643-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0643.html"/>
        <reference source="CVE" ref_id="CVE-2013-0646" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0646.html"/>
        <reference source="CVE" ref_id="CVE-2013-0650" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0650.html"/>
        <reference source="CVE" ref_id="CVE-2013-1371" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1371.html"/>
        <reference source="CVE" ref_id="CVE-2013-1375" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1375.html"/>
        <description>Heap-based buffer overflow in Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on Windows and Mac OS X, before 10.3.183.68 and 11.x before 11.2.202.275 on Linux, before 11.1.111.44 on Android 2.x and 3.x, and before 11.1.115.48 on Android 4.x; Adobe AIR before 3.6.0.6090; Adobe AIR SDK before 3.6.0.6090; and Adobe AIR SDK &amp; Compiler before 3.6.0.6090 allows attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:44.766-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:33.071-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:40.295-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20806 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:20.190-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:21.608-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.275-2.el5" test_ref="oval:org.mitre.oval:tst:137654"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.275-2.el6" test_ref="oval:org.mitre.oval:tst:91012"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20805" version="5" class="patch">
      <metadata>
        <title>RHSA-2013:1861: nss security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>nss</product>
          <product>nss-util</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1861-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1861.html"/>
        <reference source="CESA" ref_id="CESA-2013:1861"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications.

It was found that a subordinate Certificate Authority (CA) mis-issued an
intermediate certificate, which could be used to conduct man-in-the-middle
attacks. This update renders that particular intermediate certificate as
untrusted. (BZ#1038894)

Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.

All NSS users should upgrade to these updated packages, which correct this
issue. After installing the update, applications using NSS must be
restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:59:01.921-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:32.899-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:40.166-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20805 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:42.815-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:11.174-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="nss-tools is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:91461"/>
            <criterion comment="nss-devel is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:91781"/>
            <criterion comment="nss is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:91128"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:92049"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="nss-tools is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:91927"/>
            <criterion comment="nss-devel is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:91770"/>
            <criterion comment="nss-sysinit is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:91693"/>
            <criterion comment="nss is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:91621"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:92107"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20801" version="243" class="patch">
      <metadata>
        <title>RHSA-2013:0254: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0254-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0254.html"/>
        <reference source="CVE" ref_id="CVE-2013-0637" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0637.html"/>
        <reference source="CVE" ref_id="CVE-2013-0638" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0638.html"/>
        <reference source="CVE" ref_id="CVE-2013-0639" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0639.html"/>
        <reference source="CVE" ref_id="CVE-2013-0642" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0642.html"/>
        <reference source="CVE" ref_id="CVE-2013-0644" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0644.html"/>
        <reference source="CVE" ref_id="CVE-2013-0645" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0645.html"/>
        <reference source="CVE" ref_id="CVE-2013-0647" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0647.html"/>
        <reference source="CVE" ref_id="CVE-2013-0649" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0649.html"/>
        <reference source="CVE" ref_id="CVE-2013-1365" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1365.html"/>
        <reference source="CVE" ref_id="CVE-2013-1366" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1366.html"/>
        <reference source="CVE" ref_id="CVE-2013-1367" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1367.html"/>
        <reference source="CVE" ref_id="CVE-2013-1368" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1368.html"/>
        <reference source="CVE" ref_id="CVE-2013-1369" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1369.html"/>
        <reference source="CVE" ref_id="CVE-2013-1370" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1370.html"/>
        <reference source="CVE" ref_id="CVE-2013-1372" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1372.html"/>
        <reference source="CVE" ref_id="CVE-2013-1373" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1373.html"/>
        <reference source="CVE" ref_id="CVE-2013-1374" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1374.html"/>
        <description>Use-after-free vulnerability in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.599 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0644 and CVE-2013-0649.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:17.398-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:32.073-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:39.146-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20801 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:25.999-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:20.213-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.270-1.el5" test_ref="oval:org.mitre.oval:tst:137717"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.270-1.el6" test_ref="oval:org.mitre.oval:tst:90452"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20796" version="7" class="patch">
      <metadata>
        <title>RHSA-2013:1402: Adobe Reader - notification of end of updates (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1402-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1402.html"/>
        <description>Adobe Reader allows users to view and print documents in Portable Document
Format (PDF). Adobe Reader 9 reached the end of its support cycle on June
26, 2013, and will not receive any more security updates. Future versions
of Adobe Acrobat Reader will not be available with Red Hat Enterprise
Linux.

The Adobe Reader packages in the Red Hat Network (RHN) channels will
continue to be available. Red Hat will continue to provide these packages
only as a courtesy to customers. Red Hat will not provide updates to the
Adobe Reader packages.

This update disables the Adobe Reader web browser plug-in, which is
available via the acroread-plugin package, to prevent the exploitation of
security issues without user interaction when a user visits a malicious web
page.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:55.059-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:31.759-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:38.922-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20796 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:42.040-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:10.912-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20796 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:24.781-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:19.898-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="acroread is earlier than 0:9.5.5-2.el5_10" test_ref="oval:org.mitre.oval:tst:137735"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.5-2.el5_10" test_ref="oval:org.mitre.oval:tst:137827"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="acroread is earlier than 0:9.5.5-1.el6_4.1" test_ref="oval:org.mitre.oval:tst:91576"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.5-1.el6_4.1" test_ref="oval:org.mitre.oval:tst:91582"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20792" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0407: libpng security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libpng</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0407-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0407.html"/>
        <reference source="CESA" ref_id="CESA-2012:0407"/>
        <reference source="CVE" ref_id="CVE-2011-3045" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3045.html"/>
        <description>Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:57.163-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:19.455-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:34.769-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpng-devel is earlier than 2:1.2.10-16.el5_8" test_ref="oval:org.mitre.oval:tst:93039"/>
            <criterion comment="libpng is earlier than 2:1.2.10-16.el5_8" test_ref="oval:org.mitre.oval:tst:92498"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpng-static is earlier than 2:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:92961"/>
            <criterion comment="libpng-devel is earlier than 2:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:92515"/>
            <criterion comment="libpng is earlier than 2:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:93147"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20791" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0216: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0216-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0216.html"/>
        <reference source="CESA" ref_id="CESA-2013:0216"/>
        <reference source="CVE" ref_id="CVE-2012-5669" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5669.html"/>
        <description>The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to BDF fonts and an incorrect calculation that triggers an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:11.113-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:31.545-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:38.706-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:90287"/>
            <criterion comment="freetype is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:89896"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:90219"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:90390"/>
            <criterion comment="freetype is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:90453"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:90435"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20790" version="42" class="patch">
      <metadata>
        <title>RHSA-2012:1102: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1102-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1102.html"/>
        <reference source="CESA" ref_id="CESA-2012:1102"/>
        <reference source="CVE" ref_id="CVE-2012-1178" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1178.html"/>
        <reference source="CVE" ref_id="CVE-2012-2318" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2318.html"/>
        <reference source="CVE" ref_id="CVE-2012-3374" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3374.html"/>
        <description>Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary code via a crafted inline image in a message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:40.665-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:19.276-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:34.527-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:93823"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:93921"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:93384"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:93887"/>
            <criterion comment="finch-devel is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:94029"/>
            <criterion comment="finch is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:94150"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:93705"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:93357"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:93791"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="pidgin-docs is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:93753"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:93997"/>
            <criterion comment="pidgin-perl is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:94106"/>
            <criterion comment="libpurple is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:94033"/>
            <criterion comment="libpurple-perl is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:93253"/>
            <criterion comment="finch-devel is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:93960"/>
            <criterion comment="finch is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:93208"/>
            <criterion comment="libpurple-devel is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:94207"/>
            <criterion comment="pidgin-devel is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:94055"/>
            <criterion comment="pidgin is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:94011"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20788" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0308: busybox security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>busybox</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0308-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0308.html"/>
        <reference source="CVE" ref_id="CVE-2006-1168" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1168.html"/>
        <reference source="CVE" ref_id="CVE-2011-2716" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2716.html"/>
        <description>The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:04.373-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:19.164-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:34.351-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="busybox-anaconda is earlier than 1:1.2.0-13.el5" test_ref="oval:org.mitre.oval:tst:92537"/>
          <criterion comment="busybox is earlier than 1:1.2.0-13.el5" test_ref="oval:org.mitre.oval:tst:93003"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20784" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0051: kvm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0051-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0051.html"/>
        <reference source="CESA" ref_id="CESA-2012:0051"/>
        <reference source="CVE" ref_id="CVE-2011-4622" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4622.html"/>
        <reference source="CVE" ref_id="CVE-2012-0029" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0029.html"/>
        <description>Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS users to cause a denial of service (QEMU crash) and possibly execute arbitrary code via crafted legacy mode packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:05.838-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:19.037-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:34.196-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="kvm is earlier than 0:83-239.el5_7.1" test_ref="oval:org.mitre.oval:tst:92799"/>
            <criterion comment="kmod-kvm is earlier than 0:83-239.el5_7.1" test_ref="oval:org.mitre.oval:tst:92795"/>
            <criterion comment="kvm-tools is earlier than 0:83-239.el5_7.1" test_ref="oval:org.mitre.oval:tst:92650"/>
            <criterion comment="kmod-kvm-debug is earlier than 0:83-239.el5_7.1" test_ref="oval:org.mitre.oval:tst:92643"/>
            <criterion comment="kvm-qemu-img is earlier than 0:83-239.el5_7.1" test_ref="oval:org.mitre.oval:tst:92415"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="kvm is earlier than 0:83-239.el5.centos.1" test_ref="oval:org.mitre.oval:tst:94508"/>
            <criterion comment="kmod-kvm is earlier than 0:83-239.el5.centos.1" test_ref="oval:org.mitre.oval:tst:94927"/>
            <criterion comment="kvm-tools is earlier than 0:83-239.el5.centos.1" test_ref="oval:org.mitre.oval:tst:94851"/>
            <criterion comment="kmod-kvm-debug is earlier than 0:83-239.el5.centos.1" test_ref="oval:org.mitre.oval:tst:94546"/>
            <criterion comment="kvm-qemu-img is earlier than 0:83-239.el5.centos.1" test_ref="oval:org.mitre.oval:tst:94880"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20778" version="59" class="patch">
      <metadata>
        <title>RHSA-2013:0275: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0275-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0275.html"/>
        <reference source="CESA" ref_id="CESA-2013:0275"/>
        <reference source="CVE" ref_id="CVE-2013-0169" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0169.html"/>
        <reference source="CVE" ref_id="CVE-2013-1484" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1484.html"/>
        <reference source="CVE" ref_id="CVE-2013-1485" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1485.html"/>
        <reference source="CVE" ref_id="CVE-2013-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1486.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 13 and earlier, 6 Update 39 and earlier, and 5.0 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:12.832-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:30.773-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:37.819-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:89753"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:90381"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:90359"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:90465"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:90370"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:90518"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:89984"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:90356"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:90162"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:89532"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20775" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0604: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0604-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0604.html"/>
        <reference source="CESA" ref_id="CESA-2013:0604"/>
        <reference source="CVE" ref_id="CVE-2013-0809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0809.html"/>
        <reference source="CVE" ref_id="CVE-2013-1493" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1493.html"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:15.428-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:30.273-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:37.462-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.36.1.11.9.el5_9" test_ref="oval:org.mitre.oval:tst:90808"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.36.1.11.9.el5_9" test_ref="oval:org.mitre.oval:tst:90843"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.36.1.11.9.el5_9" test_ref="oval:org.mitre.oval:tst:90669"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.36.1.11.9.el5_9" test_ref="oval:org.mitre.oval:tst:90917"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.36.1.11.9.el5_9" test_ref="oval:org.mitre.oval:tst:90915"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20774" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0611: ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0611-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0611.html"/>
        <reference source="CESA" ref_id="CESA-2013:0611"/>
        <reference source="CVE" ref_id="CVE-2013-1821" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1821.html"/>
        <description>lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows remote attackers to cause a denial of service (memory consumption and crash) via crafted text nodes in an XML document, aka an XML Entity Expansion (XEE) attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:30.319-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:30.141-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:37.256-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="ruby-devel is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:90831"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:90782"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:90794"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:90960"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:90513"/>
          <criterion comment="ruby is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:90626"/>
          <criterion comment="ruby-mode is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:90116"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:90468"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:90858"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20773" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:0769: glibc security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0769-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0769.html"/>
        <reference source="CESA" ref_id="CESA-2013:0769"/>
        <reference source="CVE" ref_id="CVE-2013-0242" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0242.html"/>
        <reference source="CVE" ref_id="CVE-2013-1914" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1914.html"/>
        <reference source="CVE" ref_id="CVE-2013-1915" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1915.html"/>
        <description>ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:33.178-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:29.957-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:37.038-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="glibc-common is earlier than 0:2.5-107.el5_9.4" test_ref="oval:org.mitre.oval:tst:91143"/>
          <criterion comment="nscd is earlier than 0:2.5-107.el5_9.4" test_ref="oval:org.mitre.oval:tst:90572"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-107.el5_9.4" test_ref="oval:org.mitre.oval:tst:90638"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-107.el5_9.4" test_ref="oval:org.mitre.oval:tst:90949"/>
          <criterion comment="glibc is earlier than 0:2.5-107.el5_9.4" test_ref="oval:org.mitre.oval:tst:91247"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-107.el5_9.4" test_ref="oval:org.mitre.oval:tst:91088"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20768" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0588: gnutls security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0588-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0588.html"/>
        <reference source="CESA" ref_id="CESA-2013:0588"/>
        <reference source="CVE" ref_id="CVE-2013-1619" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1619.html"/>
        <description>The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:48.588-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:29.192-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:36.333-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="gnutls is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:89803"/>
            <criterion comment="gnutls-devel is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90567"/>
            <criterion comment="gnutls-utils is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90402"/>
            <criterion comment="gnutls-guile is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90730"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="gnutls is earlier than 0:1.4.1-10.el5_9.1" test_ref="oval:org.mitre.oval:tst:90776"/>
            <criterion comment="gnutls-devel is earlier than 0:1.4.1-10.el5_9.1" test_ref="oval:org.mitre.oval:tst:90723"/>
            <criterion comment="gnutls-utils is earlier than 0:1.4.1-10.el5_9.1" test_ref="oval:org.mitre.oval:tst:90443"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20767" version="115" class="patch">
      <metadata>
        <title>RHSA-2013:1268: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1268-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1268.html"/>
        <reference source="CESA" ref_id="CESA-2013:1268"/>
        <reference source="CVE" ref_id="CVE-2013-1718" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1718.html"/>
        <reference source="CVE" ref_id="CVE-2013-1722" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1722.html"/>
        <reference source="CVE" ref_id="CVE-2013-1725" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1725.html"/>
        <reference source="CVE" ref_id="CVE-2013-1730" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1730.html"/>
        <reference source="CVE" ref_id="CVE-2013-1732" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1732.html"/>
        <reference source="CVE" ref_id="CVE-2013-1735" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1735.html"/>
        <reference source="CVE" ref_id="CVE-2013-1736" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1736.html"/>
        <reference source="CVE" ref_id="CVE-2013-1737" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1737.html"/>
        <description>Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the "this" object during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expando object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:32.096-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:28.770-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:35.904-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:91019"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:91674"/>
            <criterion comment="firefox is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:91081"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner is earlier than 0:17.0.9-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92283"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.9-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92118"/>
            <criterion comment="firefox is earlier than 0:17.0.9-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92173"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:91516"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:91150"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:17.0.9-1.el5.centos" test_ref="oval:org.mitre.oval:tst:92110"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:91648"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20761" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0847: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0847-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0847.html"/>
        <reference source="CESA" ref_id="CESA-2013:0847"/>
        <reference source="CVE" ref_id="CVE-2013-0153" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0153.html"/>
        <description>The AMD IOMMU support in Xen 4.2.x, 4.1.x, 3.3, and other versions, when using AMD-Vi for PCI passthrough, uses the same interrupt remapping table for the host and all guests, which allows guests to cause a denial of service by injecting an interrupt into other guests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:21.588-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:28.365-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:35.411-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:91131"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:90891"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:90604"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:91213"/>
          <criterion comment="kernel is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:91200"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:90749"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:91278"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:91290"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:90836"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:91270"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:91291"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:90362"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20759" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0312: initscripts security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>initscripts</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0312-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0312.html"/>
        <reference source="CVE" ref_id="CVE-2008-1198" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1198.html"/>
        <description>The default IPSec ifup script in Red Hat Enterprise Linux 3 through 5 configures racoon to use aggressive IKE mode instead of main IKE mode, which makes it easier for remote attackers to conduct brute force attacks by sniffing an unencrypted preshared key (PSK) hash.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:18.261-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:18.894-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:33.679-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="initscripts is earlier than 0:8.45.42-1.el5" test_ref="oval:org.mitre.oval:tst:92721"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20754" version="133" class="patch">
      <metadata>
        <title>RHSA-2012:0322: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0322-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0322.html"/>
        <reference source="CVE" ref_id="CVE-2011-3563" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3563.html"/>
        <reference source="CVE" ref_id="CVE-2011-3571" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3571.html"/>
        <reference source="CVE" ref_id="CVE-2011-5035" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-5035.html"/>
        <reference source="CVE" ref_id="CVE-2012-0497" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0497.html"/>
        <reference source="CVE" ref_id="CVE-2012-0501" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0501.html"/>
        <reference source="CVE" ref_id="CVE-2012-0502" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0502.html"/>
        <reference source="CVE" ref_id="CVE-2012-0503" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0503.html"/>
        <reference source="CVE" ref_id="CVE-2012-0505" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0505.html"/>
        <reference source="CVE" ref_id="CVE-2012-0506" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0506.html"/>
        <reference source="CVE" ref_id="CVE-2012-0507" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0507.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency.  NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions.  NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:41.638-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:18.488-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:33.046-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.25.1.10.6.el5_8" test_ref="oval:org.mitre.oval:tst:92393"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.25.1.10.6.el5_8" test_ref="oval:org.mitre.oval:tst:92453"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.25.1.10.6.el5_8" test_ref="oval:org.mitre.oval:tst:92253"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.25.1.10.6.el5_8" test_ref="oval:org.mitre.oval:tst:92394"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.25.1.10.6.el5_8" test_ref="oval:org.mitre.oval:tst:93045"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20750" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0898: mesa security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>mesa</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0898-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0898.html"/>
        <reference source="CESA" ref_id="CESA-2013:0898"/>
        <reference source="CVE" ref_id="CVE-2013-1993" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1993.html"/>
        <description>Multiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XF86DRIOpenConnection and (2) XF86DRIGetClientDriverName functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:30.837-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:26.746-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:33.918-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mesa-libGLw is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:91301"/>
          <criterion comment="glx-utils is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:91369"/>
          <criterion comment="mesa-libGLU is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:91396"/>
          <criterion comment="mesa-libGL-devel is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:91321"/>
          <criterion comment="mesa-libGLU-devel is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:90970"/>
          <criterion comment="mesa-source is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:91072"/>
          <criterion comment="mesa-libGLw-devel is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:91313"/>
          <criterion comment="mesa-libOSMesa is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:91372"/>
          <criterion comment="mesa-libGL is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:90814"/>
          <criterion comment="mesa-libOSMesa-devel is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:90953"/>
          <criterion comment="mesa is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:90417"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20749" version="117" class="patch">
      <metadata>
        <title>RHSA-2013:1812: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1812-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1812.html"/>
        <reference source="CESA" ref_id="CESA-2013:1812"/>
        <reference source="CVE" ref_id="CVE-2013-0772" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0772.html"/>
        <reference source="CVE" ref_id="CVE-2013-5609" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5609.html"/>
        <reference source="CVE" ref_id="CVE-2013-5612" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5612.html"/>
        <reference source="CVE" ref_id="CVE-2013-5613" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5613.html"/>
        <reference source="CVE" ref_id="CVE-2013-5614" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5614.html"/>
        <reference source="CVE" ref_id="CVE-2013-5616" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5616.html"/>
        <reference source="CVE" ref_id="CVE-2013-5618" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5618.html"/>
        <reference source="CVE" ref_id="CVE-2013-6671" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6671.html"/>
        <description>The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code via crafted use of JavaScript code for ordered list elements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:45.951-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:26.397-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:33.610-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20749 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:38.262-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:08.832-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:24.2.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:91963"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:24.2.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:91784"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="firefox is earlier than 0:24.2.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:91755"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="firefox is earlier than 0:24.2.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92230"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20740" version="369" class="patch">
      <metadata>
        <title>RHSA-2013:0826: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0826-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0826.html"/>
        <reference source="CVE" ref_id="CVE-2013-2549" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2549.html"/>
        <reference source="CVE" ref_id="CVE-2013-2718" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2718.html"/>
        <reference source="CVE" ref_id="CVE-2013-2719" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2719.html"/>
        <reference source="CVE" ref_id="CVE-2013-2720" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2720.html"/>
        <reference source="CVE" ref_id="CVE-2013-2721" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2721.html"/>
        <reference source="CVE" ref_id="CVE-2013-2722" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2722.html"/>
        <reference source="CVE" ref_id="CVE-2013-2723" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2723.html"/>
        <reference source="CVE" ref_id="CVE-2013-2724" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2724.html"/>
        <reference source="CVE" ref_id="CVE-2013-2725" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2725.html"/>
        <reference source="CVE" ref_id="CVE-2013-2726" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2726.html"/>
        <reference source="CVE" ref_id="CVE-2013-2727" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2727.html"/>
        <reference source="CVE" ref_id="CVE-2013-2729" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2729.html"/>
        <reference source="CVE" ref_id="CVE-2013-2730" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2730.html"/>
        <reference source="CVE" ref_id="CVE-2013-2731" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2731.html"/>
        <reference source="CVE" ref_id="CVE-2013-2732" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2732.html"/>
        <reference source="CVE" ref_id="CVE-2013-2733" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2733.html"/>
        <reference source="CVE" ref_id="CVE-2013-2734" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2734.html"/>
        <reference source="CVE" ref_id="CVE-2013-2735" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2735.html"/>
        <reference source="CVE" ref_id="CVE-2013-2736" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2736.html"/>
        <reference source="CVE" ref_id="CVE-2013-2737" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2737.html"/>
        <reference source="CVE" ref_id="CVE-2013-3337" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3337.html"/>
        <reference source="CVE" ref_id="CVE-2013-3338" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3338.html"/>
        <reference source="CVE" ref_id="CVE-2013-3339" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3339.html"/>
        <reference source="CVE" ref_id="CVE-2013-3340" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3340.html"/>
        <reference source="CVE" ref_id="CVE-2013-3341" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3341.html"/>
        <reference source="CVE" ref_id="CVE-2013-3346" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3346.html"/>
        <description>Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:18.777-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:23.747-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:30.842-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20740 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:32.055-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:17.794-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="acroread is earlier than 0:9.5.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:137039"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:137850"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="acroread is earlier than 0:9.5.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:90995"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:91164"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20731" version="5" class="patch">
      <metadata>
        <title>RHSA-2013:0214: nss and nspr security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>nspr</product>
          <product>nss</product>
          <product>nss-util</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0214-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0214.html"/>
        <reference source="CESA" ref_id="CESA-2013:0214"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

It was found that a Certificate Authority (CA) mis-issued two intermediate
certificates to customers. These certificates could be used to launch
man-in-the-middle attacks. This update renders those certificates as
untrusted. This covers all uses of the certificates, including SSL, S/MIME,
and code signing. (BZ#890605)

In addition, the nss package has been upgraded to upstream version 3.13.6,
and the nspr package has been upgraded to upstream version 4.9.2. These
updates provide a number of bug fixes and enhancements over the previous
versions. (BZ#893371, BZ#893372)

All NSS and NSPR users should upgrade to these updated packages, which
correct these issues and add these enhancements. After installing the
update, applications using NSS and NSPR must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:18.237-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:23.048-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:30.011-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20731 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:42.157-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:08.544-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="nspr-devel is earlier than 0:4.9.2-2.el5_9" test_ref="oval:org.mitre.oval:tst:90485"/>
          <criterion comment="nspr is earlier than 0:4.9.2-2.el5_9" test_ref="oval:org.mitre.oval:tst:90201"/>
          <criterion comment="nss is earlier than 0:3.13.6-3.el5_9" test_ref="oval:org.mitre.oval:tst:90142"/>
          <criterion comment="nss-devel is earlier than 0:3.13.6-3.el5_9" test_ref="oval:org.mitre.oval:tst:90018"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.13.6-3.el5_9" test_ref="oval:org.mitre.oval:tst:90109"/>
          <criterion comment="nss-tools is earlier than 0:3.13.6-3.el5_9" test_ref="oval:org.mitre.oval:tst:90379"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20719" version="68" class="patch">
      <metadata>
        <title>RHSA-2012:0079: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0079-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0079.html"/>
        <reference source="CESA" ref_id="CESA-2012:0079"/>
        <reference source="CVE" ref_id="CVE-2011-3659" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3659.html"/>
        <reference source="CVE" ref_id="CVE-2011-3670" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3670.html"/>
        <reference source="CVE" ref_id="CVE-2012-0442" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0442.html"/>
        <reference source="CVE" ref_id="CVE-2012-0444" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0444.html"/>
        <reference source="CVE" ref_id="CVE-2012-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0449.html"/>
        <description>Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed XSLT stylesheet that is embedded in a document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:16.263-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:17.857-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:32.218-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-1.el6_2" test_ref="oval:org.mitre.oval:tst:92809"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-1.el6_2" test_ref="oval:org.mitre.oval:tst:92255"/>
            <criterion comment="firefox is earlier than 0:3.6.26-1.el6_2" test_ref="oval:org.mitre.oval:tst:92852"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94231"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94932"/>
            <criterion comment="firefox is earlier than 0:3.6.26-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94032"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-1.el5_7" test_ref="oval:org.mitre.oval:tst:92621"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-1.el5_7" test_ref="oval:org.mitre.oval:tst:92651"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:3.6.26-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94504"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:3.6.26-1.el5_7" test_ref="oval:org.mitre.oval:tst:92761"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20714" version="33" class="patch">
      <metadata>
        <title>RHSA-2013:1518: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1518-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1518.html"/>
        <reference source="CVE" ref_id="CVE-2013-5329" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5329.html"/>
        <reference source="CVE" ref_id="CVE-2013-5330" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5330.html"/>
        <description>Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK &amp; Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5329.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:15.054-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:22.008-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:28.780-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20714 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:05.143-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:17.372-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.327-1.el5" test_ref="oval:org.mitre.oval:tst:137635"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.327-1.el6" test_ref="oval:org.mitre.oval:tst:91385"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20713" version="311" class="patch">
      <metadata>
        <title>RHSA-2013:0752: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0752-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0752.html"/>
        <reference source="CESA" ref_id="CESA-2013:0752"/>
        <reference source="CVE" ref_id="CVE-2013-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0401.html"/>
        <reference source="CVE" ref_id="CVE-2013-1488" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1488.html"/>
        <reference source="CVE" ref_id="CVE-2013-1518" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1518.html"/>
        <reference source="CVE" ref_id="CVE-2013-1537" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1537.html"/>
        <reference source="CVE" ref_id="CVE-2013-1557" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1557.html"/>
        <reference source="CVE" ref_id="CVE-2013-1558" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1558.html"/>
        <reference source="CVE" ref_id="CVE-2013-1569" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1569.html"/>
        <reference source="CVE" ref_id="CVE-2013-2383" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2383.html"/>
        <reference source="CVE" ref_id="CVE-2013-2384" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2384.html"/>
        <reference source="CVE" ref_id="CVE-2013-2415" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2415.html"/>
        <reference source="CVE" ref_id="CVE-2013-2417" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2417.html"/>
        <reference source="CVE" ref_id="CVE-2013-2419" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2419.html"/>
        <reference source="CVE" ref_id="CVE-2013-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2420.html"/>
        <reference source="CVE" ref_id="CVE-2013-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2421.html"/>
        <reference source="CVE" ref_id="CVE-2013-2422" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2422.html"/>
        <reference source="CVE" ref_id="CVE-2013-2423" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2423.html"/>
        <reference source="CVE" ref_id="CVE-2013-2424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2424.html"/>
        <reference source="CVE" ref_id="CVE-2013-2426" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2426.html"/>
        <reference source="CVE" ref_id="CVE-2013-2429" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2429.html"/>
        <reference source="CVE" ref_id="CVE-2013-2430" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2430.html"/>
        <reference source="CVE" ref_id="CVE-2013-2431" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2431.html"/>
        <reference source="CVE" ref_id="CVE-2013-2437" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2437.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:37.648-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:21.320-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:28.190-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.19-2.3.9.1.el5_9" test_ref="oval:org.mitre.oval:tst:91007"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.19-2.3.9.1.el5_9" test_ref="oval:org.mitre.oval:tst:90828"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.19-2.3.9.1.el5_9" test_ref="oval:org.mitre.oval:tst:91235"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.19-2.3.9.1.el5_9" test_ref="oval:org.mitre.oval:tst:91240"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.19-2.3.9.1.el5_9" test_ref="oval:org.mitre.oval:tst:91066"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20704" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0523: libpng security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libpng</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0523-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0523.html"/>
        <reference source="CESA" ref_id="CESA-2012:0523"/>
        <reference source="CVE" ref_id="CVE-2011-3048" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3048.html"/>
        <description>The png_set_text_2 function in pngset.c in libpng 1.0.x before 1.0.59, 1.2.x before 1.2.49, 1.4.x before 1.4.11, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted text chunk in a PNG image file, which triggers a memory allocation failure that is not properly handled, leading to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:39.789-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:17.700-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:31.982-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpng-devel is earlier than 2:1.2.10-17.el5_8" test_ref="oval:org.mitre.oval:tst:92895"/>
            <criterion comment="libpng is earlier than 2:1.2.10-17.el5_8" test_ref="oval:org.mitre.oval:tst:93394"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpng-static is earlier than 2:1.2.49-1.el6_2" test_ref="oval:org.mitre.oval:tst:93233"/>
            <criterion comment="libpng-devel is earlier than 2:1.2.49-1.el6_2" test_ref="oval:org.mitre.oval:tst:93402"/>
            <criterion comment="libpng is earlier than 2:1.2.49-1.el6_2" test_ref="oval:org.mitre.oval:tst:93355"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20703" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0332: samba security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0332-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0332.html"/>
        <reference source="CVE" ref_id="CVE-2012-0870" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0870.html"/>
        <description>Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a Batched (aka AndX) request that triggers infinite recursion.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:53.067-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:17.605-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:31.871-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libsmbclient is earlier than 0:3.0.33-3.38.el5_8" test_ref="oval:org.mitre.oval:tst:93015"/>
          <criterion comment="samba is earlier than 0:3.0.33-3.38.el5_8" test_ref="oval:org.mitre.oval:tst:92384"/>
          <criterion comment="samba-swat is earlier than 0:3.0.33-3.38.el5_8" test_ref="oval:org.mitre.oval:tst:92980"/>
          <criterion comment="samba-client is earlier than 0:3.0.33-3.38.el5_8" test_ref="oval:org.mitre.oval:tst:93065"/>
          <criterion comment="samba-common is earlier than 0:3.0.33-3.38.el5_8" test_ref="oval:org.mitre.oval:tst:93075"/>
          <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.38.el5_8" test_ref="oval:org.mitre.oval:tst:92938"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20691" version="143" class="patch">
      <metadata>
        <title>RHSA-2013:0981: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0981-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0981.html"/>
        <reference source="CESA" ref_id="CESA-2013:0981"/>
        <reference source="CVE" ref_id="CVE-2013-1682" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1682.html"/>
        <reference source="CVE" ref_id="CVE-2013-1684" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1684.html"/>
        <reference source="CVE" ref_id="CVE-2013-1685" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1685.html"/>
        <reference source="CVE" ref_id="CVE-2013-1686" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1686.html"/>
        <reference source="CVE" ref_id="CVE-2013-1687" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1687.html"/>
        <reference source="CVE" ref_id="CVE-2013-1690" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1690.html"/>
        <reference source="CVE" ref_id="CVE-2013-1692" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1692.html"/>
        <reference source="CVE" ref_id="CVE-2013-1693" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1693.html"/>
        <reference source="CVE" ref_id="CVE-2013-1694" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1694.html"/>
        <reference source="CVE" ref_id="CVE-2013-1697" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1697.html"/>
        <description>The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly restrict use of DefaultValue for method calls, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that triggers use of a user-defined (1) toString or (2) valueOf method.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:59:07.260-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:20.693-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:27.341-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:90913"/>
            <criterion comment="xulrunner is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:91242"/>
            <criterion comment="firefox is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:91355"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.7-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92100"/>
            <criterion comment="xulrunner is earlier than 0:17.0.7-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92264"/>
            <criterion comment="firefox is earlier than 0:17.0.7-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92047"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:91488"/>
            <criterion comment="xulrunner is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:91443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:17.0.7-1.el5.centos" test_ref="oval:org.mitre.oval:tst:91490"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:91455"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20690" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:1459: gnupg2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>gnupg2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1459-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1459.html"/>
        <reference source="CESA" ref_id="CESA-2013:1459"/>
        <reference source="CVE" ref_id="CVE-2012-6085" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6085.html"/>
        <reference source="CVE" ref_id="CVE-2013-4351" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4351.html"/>
        <reference source="CVE" ref_id="CVE-2013-4402" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4402.html"/>
        <description>The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recursion) via a crafted OpenPGP message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:16.780-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:20.531-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:27.129-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="gnupg2 is earlier than 0:2.0.14-6.el6_4" test_ref="oval:org.mitre.oval:tst:91783"/>
            <criterion comment="gnupg2-smime is earlier than 0:2.0.14-6.el6_4" test_ref="oval:org.mitre.oval:tst:91724"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="gnupg2 is earlier than 0:2.0.10-6.el5_10" test_ref="oval:org.mitre.oval:tst:91826"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20689" version="42" class="patch">
      <metadata>
        <title>RHSA-2012:1407: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1407-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1407.html"/>
        <reference source="CESA" ref_id="CESA-2012:1407"/>
        <reference source="CVE" ref_id="CVE-2012-4194" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4194.html"/>
        <reference source="CVE" ref_id="CVE-2012-4195" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4195.html"/>
        <reference source="CVE" ref_id="CVE-2012-4196" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4196.html"/>
        <description>Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:52.539-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:17.225-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:31.318-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:94479"/>
            <criterion comment="xulrunner is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:94572"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:10.0.10-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94825"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:94822"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:94792"/>
            <criterion comment="xulrunner is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:94695"/>
            <criterion comment="firefox is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:94827"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.10-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94926"/>
            <criterion comment="xulrunner is earlier than 0:10.0.10-1.el6.centos" test_ref="oval:org.mitre.oval:tst:95064"/>
            <criterion comment="firefox is earlier than 0:10.0.10-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94937"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20665" version="94" class="patch">
      <metadata>
        <title>RHSA-2012:1255: libexif security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libexif</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1255-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1255.html"/>
        <reference source="CESA" ref_id="CESA-2012:1255"/>
        <reference source="CVE" ref_id="CVE-2012-2812" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2812.html"/>
        <reference source="CVE" ref_id="CVE-2012-2813" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2813.html"/>
        <reference source="CVE" ref_id="CVE-2012-2814" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2814.html"/>
        <reference source="CVE" ref_id="CVE-2012-2836" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2836.html"/>
        <reference source="CVE" ref_id="CVE-2012-2837" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2837.html"/>
        <reference source="CVE" ref_id="CVE-2012-2840" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2840.html"/>
        <reference source="CVE" ref_id="CVE-2012-2841" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2841.html"/>
        <description>Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remote attackers to execute arbitrary code via vectors involving a crafted buffer-size parameter during the formatting of an EXIF tag, leading to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:27.463-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:16.617-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:30.624-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libexif-devel is earlier than 0:0.6.21-1.el5_8" test_ref="oval:org.mitre.oval:tst:94462"/>
            <criterion comment="libexif is earlier than 0:0.6.21-1.el5_8" test_ref="oval:org.mitre.oval:tst:94215"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libexif-devel is earlier than 0:0.6.21-5.el6_3" test_ref="oval:org.mitre.oval:tst:94469"/>
            <criterion comment="libexif is earlier than 0:0.6.21-5.el6_3" test_ref="oval:org.mitre.oval:tst:94356"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20660" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1302: xinetd security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>xinetd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1302-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1302.html"/>
        <reference source="CESA" ref_id="CESA-2013:1302"/>
        <reference source="CVE" ref_id="CVE-2012-0862" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0862.html"/>
        <description>builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which exposes all enabled services and allows remote attackers to bypass intended access restrictions via a request to tcpmux port 1.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:22.206-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:20.438-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:27.011-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="xinetd is earlier than 2:2.3.14-19.el5" test_ref="oval:org.mitre.oval:tst:91480"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20642" version="299" class="patch">
      <metadata>
        <title>RHSA-2013:1509: java-1.5.0-ibm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1509-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1509.html"/>
        <reference source="CVE" ref_id="CVE-2013-5774" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5774.html"/>
        <reference source="CVE" ref_id="CVE-2013-5778" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5778.html"/>
        <reference source="CVE" ref_id="CVE-2013-5780" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5780.html"/>
        <reference source="CVE" ref_id="CVE-2013-5782" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5782.html"/>
        <reference source="CVE" ref_id="CVE-2013-5783" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5783.html"/>
        <reference source="CVE" ref_id="CVE-2013-5790" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5790.html"/>
        <reference source="CVE" ref_id="CVE-2013-5797" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5797.html"/>
        <reference source="CVE" ref_id="CVE-2013-5801" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5801.html"/>
        <reference source="CVE" ref_id="CVE-2013-5802" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5802.html"/>
        <reference source="CVE" ref_id="CVE-2013-5803" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5803.html"/>
        <reference source="CVE" ref_id="CVE-2013-5804" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5804.html"/>
        <reference source="CVE" ref_id="CVE-2013-5809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5809.html"/>
        <reference source="CVE" ref_id="CVE-2013-5814" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5814.html"/>
        <reference source="CVE" ref_id="CVE-2013-5817" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5817.html"/>
        <reference source="CVE" ref_id="CVE-2013-5825" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5825.html"/>
        <reference source="CVE" ref_id="CVE-2013-5829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5829.html"/>
        <reference source="CVE" ref_id="CVE-2013-5830" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5830.html"/>
        <reference source="CVE" ref_id="CVE-2013-5840" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5840.html"/>
        <reference source="CVE" ref_id="CVE-2013-5842" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5842.html"/>
        <reference source="CVE" ref_id="CVE-2013-5843" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5843.html"/>
        <reference source="CVE" ref_id="CVE-2013-5849" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5849.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via vectors related to AWT.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:46.973-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:19.413-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:25.911-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20642 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:24.559-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:15.485-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.4-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137682"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.4-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137753"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.4-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137820"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.4-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137845"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.4-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137839"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.4-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137173"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.4-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137784"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.4-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137461"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91630"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91332"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91325"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91727"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91915"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91799"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91583"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20636" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0788: subscription-manager security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>subscription-manager</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0788-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0788.html"/>
        <reference source="CVE" ref_id="CVE-2012-6137" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6137.html"/>
        <description>rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X.509 certificate when migrating to a Certificate-based Red Hat Network, which allows remote man-in-the-middle attackers to obtain sensitive information such as user credentials.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:16.174-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:19.247-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:25.700-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="subscription-manager-firstboot is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:90947"/>
            <criterion comment="subscription-manager-gui is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:91230"/>
            <criterion comment="subscription-manager-migration is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:91218"/>
            <criterion comment="subscription-manager is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:91189"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="subscription-manager-firstboot is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:91246"/>
            <criterion comment="subscription-manager-gui is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:91199"/>
            <criterion comment="subscription-manager-migration is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:90783"/>
            <criterion comment="subscription-manager is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:90886"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20604" version="87" class="patch">
      <metadata>
        <title>RHSA-2013:1140: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1140-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1140.html"/>
        <reference source="CESA" ref_id="CESA-2013:1140"/>
        <reference source="CVE" ref_id="CVE-2013-1701" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1701.html"/>
        <reference source="CVE" ref_id="CVE-2013-1709" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1709.html"/>
        <reference source="CVE" ref_id="CVE-2013-1710" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1710.html"/>
        <reference source="CVE" ref_id="CVE-2013-1713" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1713.html"/>
        <reference source="CVE" ref_id="CVE-2013-1714" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1714.html"/>
        <reference source="CVE" ref_id="CVE-2013-1717" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1717.html"/>
        <description>Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly restrict local-filesystem access by Java applets, which allows user-assisted remote attackers to read arbitrary files by leveraging a download to a fixed pathname or other predictable pathname.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:18.500-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:17.781-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:24.539-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:17.0.8-1.el6_4" test_ref="oval:org.mitre.oval:tst:91594"/>
            <criterion comment="xulrunner is earlier than 0:17.0.8-3.el6_4" test_ref="oval:org.mitre.oval:tst:90631"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.8-3.el6_4" test_ref="oval:org.mitre.oval:tst:91370"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:17.0.8-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92028"/>
            <criterion comment="xulrunner is earlier than 0:17.0.8-3.el6.centos" test_ref="oval:org.mitre.oval:tst:92196"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.8-3.el6.centos" test_ref="oval:org.mitre.oval:tst:91976"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner is earlier than 0:17.0.8-3.el5_9" test_ref="oval:org.mitre.oval:tst:91285"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.8-3.el5_9" test_ref="oval:org.mitre.oval:tst:91530"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:17.0.8-1.el5.centos" test_ref="oval:org.mitre.oval:tst:92126"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:17.0.8-1.el5_9" test_ref="oval:org.mitre.oval:tst:90982"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20603" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1411: glibc security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1411-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1411.html"/>
        <reference source="CESA" ref_id="CESA-2013:1411"/>
        <reference source="CVE" ref_id="CVE-2013-4336" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4336.html"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:45.327-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:17.625-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:24.245-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="nscd is earlier than 0:2.5-118.el5_10.2" test_ref="oval:org.mitre.oval:tst:91634"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-118.el5_10.2" test_ref="oval:org.mitre.oval:tst:91103"/>
          <criterion comment="glibc-common is earlier than 0:2.5-118.el5_10.2" test_ref="oval:org.mitre.oval:tst:91632"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-118.el5_10.2" test_ref="oval:org.mitre.oval:tst:91366"/>
          <criterion comment="glibc is earlier than 0:2.5-118.el5_10.2" test_ref="oval:org.mitre.oval:tst:91102"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-118.el5_10.2" test_ref="oval:org.mitre.oval:tst:91405"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20599" version="28" class="patch">
      <metadata>
        <title>RHSA-2012:0152: kexec-tools security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>kexec-tools</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0152-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0152.html"/>
        <reference source="CVE" ref_id="CVE-2011-3588" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3588.html"/>
        <reference source="CVE" ref_id="CVE-2011-3589" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3589.html"/>
        <reference source="CVE" ref_id="CVE-2011-3590" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3590.html"/>
        <description>The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat Enterprise Linux, includes all of root's SSH private keys within a vmcore file, which allows context-dependent attackers to obtain sensitive information by inspecting the file content.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:19.801-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:15.177-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:28.819-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criterion comment="kexec-tools is earlier than 0:1.102pre-154.el5" test_ref="oval:org.mitre.oval:tst:92841"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20582" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0301: ImageMagick security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>ImageMagick</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0301-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0301.html"/>
        <reference source="CVE" ref_id="CVE-2010-4167" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4167.html"/>
        <description>Untrusted search path vulnerability in configure.c in ImageMagick before 6.6.5-5, when MAGICKCORE_INSTALLED_SUPPORT is defined, allows local users to gain privileges via a Trojan horse configuration file in the current working directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:03.790-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:14.934-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:28.555-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="ImageMagick-devel is earlier than 0:6.2.8.0-12.el5" test_ref="oval:org.mitre.oval:tst:92941"/>
          <criterion comment="ImageMagick is earlier than 0:6.2.8.0-12.el5" test_ref="oval:org.mitre.oval:tst:92848"/>
          <criterion comment="ImageMagick-c++ is earlier than 0:6.2.8.0-12.el5" test_ref="oval:org.mitre.oval:tst:92994"/>
          <criterion comment="ImageMagick-c++-devel is earlier than 0:6.2.8.0-12.el5" test_ref="oval:org.mitre.oval:tst:93034"/>
          <criterion comment="ImageMagick-perl is earlier than 0:6.2.8.0-12.el5" test_ref="oval:org.mitre.oval:tst:92425"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20575" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0274: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0274-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0274.html"/>
        <reference source="CESA" ref_id="CESA-2013:0274"/>
        <reference source="CVE" ref_id="CVE-2013-0169" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0169.html"/>
        <reference source="CVE" ref_id="CVE-2013-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1486.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 13 and earlier, 6 Update 39 and earlier, and 5.0 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:14.453-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:16.077-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:21.631-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.35.1.11.8.el5_9" test_ref="oval:org.mitre.oval:tst:90039"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.35.1.11.8.el5_9" test_ref="oval:org.mitre.oval:tst:90199"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.35.1.11.8.el5_9" test_ref="oval:org.mitre.oval:tst:90324"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.35.1.11.8.el5_9" test_ref="oval:org.mitre.oval:tst:89959"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.35.1.11.8.el5_9" test_ref="oval:org.mitre.oval:tst:89841"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20541" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0731: expat security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>expat</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0731-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0731.html"/>
        <reference source="CESA" ref_id="CESA-2012:0731"/>
        <reference source="CVE" ref_id="CVE-2012-0876" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0876.html"/>
        <reference source="CVE" ref_id="CVE-2012-1148" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1148.html"/>
        <description>Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:45.074-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:14.663-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:28.232-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="expat-devel is earlier than 0:1.95.8-11.el5_8" test_ref="oval:org.mitre.oval:tst:93627"/>
            <criterion comment="expat is earlier than 0:1.95.8-11.el5_8" test_ref="oval:org.mitre.oval:tst:93421"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="expat-devel is earlier than 0:2.0.1-11.el6_2" test_ref="oval:org.mitre.oval:tst:93827"/>
            <criterion comment="expat is earlier than 0:2.0.1-11.el6_2" test_ref="oval:org.mitre.oval:tst:93425"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20470" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0121: mysql security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0121-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0121.html"/>
        <reference source="CESA" ref_id="CESA-2013:0121"/>
        <reference source="CVE" ref_id="CVE-2012-4452" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4452.html"/>
        <description>MySQL 5.0.88, and possibly other versions and platforms, allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value.  NOTE: this vulnerability exists because of a CVE-2009-4030 regression, which was not omitted in other packages and versions such as MySQL 5.0.95 in Red Hat Enterprise Linux 6.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:02.306-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:15.088-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:20.239-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mysql-server is earlier than 0:5.0.95-3.el5" test_ref="oval:org.mitre.oval:tst:90101"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.95-3.el5" test_ref="oval:org.mitre.oval:tst:89492"/>
          <criterion comment="mysql is earlier than 0:5.0.95-3.el5" test_ref="oval:org.mitre.oval:tst:89869"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.95-3.el5" test_ref="oval:org.mitre.oval:tst:89772"/>
          <criterion comment="mysql-test is earlier than 0:5.0.95-3.el5" test_ref="oval:org.mitre.oval:tst:89627"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20467" version="283" class="patch">
      <metadata>
        <title>RHSA-2013:0770: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0770-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0770.html"/>
        <reference source="CESA" ref_id="CESA-2013:0770"/>
        <reference source="CVE" ref_id="CVE-2013-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0401.html"/>
        <reference source="CVE" ref_id="CVE-2013-1488" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1488.html"/>
        <reference source="CVE" ref_id="CVE-2013-1518" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1518.html"/>
        <reference source="CVE" ref_id="CVE-2013-1537" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1537.html"/>
        <reference source="CVE" ref_id="CVE-2013-1557" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1557.html"/>
        <reference source="CVE" ref_id="CVE-2013-1558" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1558.html"/>
        <reference source="CVE" ref_id="CVE-2013-1569" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1569.html"/>
        <reference source="CVE" ref_id="CVE-2013-2383" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2383.html"/>
        <reference source="CVE" ref_id="CVE-2013-2384" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2384.html"/>
        <reference source="CVE" ref_id="CVE-2013-2415" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2415.html"/>
        <reference source="CVE" ref_id="CVE-2013-2417" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2417.html"/>
        <reference source="CVE" ref_id="CVE-2013-2419" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2419.html"/>
        <reference source="CVE" ref_id="CVE-2013-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2420.html"/>
        <reference source="CVE" ref_id="CVE-2013-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2421.html"/>
        <reference source="CVE" ref_id="CVE-2013-2422" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2422.html"/>
        <reference source="CVE" ref_id="CVE-2013-2424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2424.html"/>
        <reference source="CVE" ref_id="CVE-2013-2426" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2426.html"/>
        <reference source="CVE" ref_id="CVE-2013-2429" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2429.html"/>
        <reference source="CVE" ref_id="CVE-2013-2430" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2430.html"/>
        <reference source="CVE" ref_id="CVE-2013-2431" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2431.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to bypassing the Java sandbox using "method handle intrinsic frames."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:11.639-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:14.288-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:19.937-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:91183"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:91018"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:91229"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:91269"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:91263"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:91271"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:91258"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:91198"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:91207"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:91091"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20445" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0359: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0359-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0359.html"/>
        <reference source="CVE" ref_id="CVE-2012-0768" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0768.html"/>
        <reference source="CVE" ref_id="CVE-2012-0769" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0769.html"/>
        <description>Adobe Flash Player before 10.3.183.16 and 11.x before 11.1.102.63 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.7 on Android 2.x and 3.x; and before 11.1.115.7 on Android 4.x does not properly handle integers, which allows attackers to obtain sensitive information via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:55.929-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:14.355-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:27.787-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.16-1.el5" test_ref="oval:org.mitre.oval:tst:92839"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.16-1.el6" test_ref="oval:org.mitre.oval:tst:92837"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20442" version="355" class="patch">
      <metadata>
        <title>RHSA-2013:0150: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0150-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0150.html"/>
        <reference source="CVE" ref_id="CVE-2012-1530" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1530.html"/>
        <reference source="CVE" ref_id="CVE-2013-0601" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0601.html"/>
        <reference source="CVE" ref_id="CVE-2013-0602" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0602.html"/>
        <reference source="CVE" ref_id="CVE-2013-0603" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0603.html"/>
        <reference source="CVE" ref_id="CVE-2013-0604" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0604.html"/>
        <reference source="CVE" ref_id="CVE-2013-0605" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0605.html"/>
        <reference source="CVE" ref_id="CVE-2013-0606" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0606.html"/>
        <reference source="CVE" ref_id="CVE-2013-0607" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0607.html"/>
        <reference source="CVE" ref_id="CVE-2013-0608" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0608.html"/>
        <reference source="CVE" ref_id="CVE-2013-0609" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0609.html"/>
        <reference source="CVE" ref_id="CVE-2013-0610" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0610.html"/>
        <reference source="CVE" ref_id="CVE-2013-0611" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0611.html"/>
        <reference source="CVE" ref_id="CVE-2013-0612" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0612.html"/>
        <reference source="CVE" ref_id="CVE-2013-0613" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0613.html"/>
        <reference source="CVE" ref_id="CVE-2013-0614" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0614.html"/>
        <reference source="CVE" ref_id="CVE-2013-0615" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0615.html"/>
        <reference source="CVE" ref_id="CVE-2013-0616" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0616.html"/>
        <reference source="CVE" ref_id="CVE-2013-0617" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0617.html"/>
        <reference source="CVE" ref_id="CVE-2013-0618" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0618.html"/>
        <reference source="CVE" ref_id="CVE-2013-0619" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0619.html"/>
        <reference source="CVE" ref_id="CVE-2013-0620" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0620.html"/>
        <reference source="CVE" ref_id="CVE-2013-0621" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0621.html"/>
        <reference source="CVE" ref_id="CVE-2013-0623" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0623.html"/>
        <reference source="CVE" ref_id="CVE-2013-0626" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0626.html"/>
        <reference source="CVE" ref_id="CVE-2013-1376" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1376.html"/>
        <description>Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0606, CVE-2013-0612, CVE-2013-0615, CVE-2013-0617, and CVE-2013-0621.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:48.385-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:13.559-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:18.855-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20442 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:28.481-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:13.455-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="acroread is earlier than 0:9.5.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:137718"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:137517"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="acroread is earlier than 0:9.5.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:90378"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:90196"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20438" version="47" class="patch">
      <metadata>
        <title>RHSA-2013:0574: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0574-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0574.html"/>
        <reference source="CVE" ref_id="CVE-2013-0504" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0504.html"/>
        <reference source="CVE" ref_id="CVE-2013-0643" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0643.html"/>
        <reference source="CVE" ref_id="CVE-2013-0648" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0648.html"/>
        <description>Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:21.134-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:13.313-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:18.571-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20438 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:21.780-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:12.971-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.273-1.el5" test_ref="oval:org.mitre.oval:tst:137667"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.273-1.el6" test_ref="oval:org.mitre.oval:tst:90634"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20413" version="83" class="patch">
      <metadata>
        <title>RHSA-2012:0144: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0144-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0144.html"/>
        <reference source="CVE" ref_id="CVE-2012-0752" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0752.html"/>
        <reference source="CVE" ref_id="CVE-2012-0753" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0753.html"/>
        <reference source="CVE" ref_id="CVE-2012-0754" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0754.html"/>
        <reference source="CVE" ref_id="CVE-2012-0755" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0755.html"/>
        <reference source="CVE" ref_id="CVE-2012-0756" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0756.html"/>
        <reference source="CVE" ref_id="CVE-2012-0767" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0767.html"/>
        <description>Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)," as exploited in the wild in February 2012.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:42.624-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:14.143-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:27.412-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20413 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:27.370-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:12.133-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.15-1.el5" test_ref="oval:org.mitre.oval:tst:137012"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.15-1.el6" test_ref="oval:org.mitre.oval:tst:92921"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20368" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:0168: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0168-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0168.html"/>
        <reference source="CESA" ref_id="CESA-2013:0168"/>
        <reference source="CVE" ref_id="CVE-2012-1568" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1568.html"/>
        <reference source="CVE" ref_id="CVE-2012-4444" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4444.html"/>
        <reference source="CVE" ref_id="CVE-2012-5515" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5515.html"/>
        <description>The (1) XENMEM_decrease_reservation, (2) XENMEM_populate_physmap, and (3) XENMEM_exchange hypercalls in Xen 4.2 and earlier allow local guest administrators to cause a denial of service (long loop and hang) via a crafted extent_order value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:24.808-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:12.846-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:18.063-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:90301"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:90139"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:90076"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:90130"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:90150"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:90349"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:90206"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:90126"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:90294"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:90235"/>
          <criterion comment="kernel is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:89623"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:90248"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20344" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0126: squirrelmail security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>squirrelmail</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0126-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0126.html"/>
        <reference source="CESA" ref_id="CESA-2013:0126"/>
        <reference source="CVE" ref_id="CVE-2012-2124" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2124.html"/>
        <description>functions/imap_general.php in SquirrelMail, as used in Red Hat Enterprise Linux (RHEL) 4 and 5, does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial of service (disk consumption) by making many IMAP login attempts with different usernames, leading to the creation of many preference files.  NOTE: this issue exists because of an incorrect fix for CVE-2010-2813.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:22.066-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:12.703-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:17.919-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-21.el5" test_ref="oval:org.mitre.oval:tst:90336"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-21.el5.centos" test_ref="oval:org.mitre.oval:tst:92117"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20291" version="6" class="patch">
      <metadata>
        <title>RHSA-2013:1860: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1860-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1860.html"/>
        <reference source="CVE" ref_id="CVE-2013-4299" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4299.html"/>
        <description>Interpretation conflict in drivers/md/dm-snap-persistent.c in the Linux kernel through 3.11.6 allows remote authenticated users to obtain sensitive information or modify data via a crafted mapping to a snapshot block device.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:09.019-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:12.233-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:17.483-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20291 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:41.589-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:04.752-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:91952"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:91539"/>
          <criterion comment="kernel is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:91866"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:91847"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:92064"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:91794"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:92061"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:92098"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:91563"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:92009"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:91124"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:92005"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20287" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0123: OpenIPMI security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>OpenIPMI</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0123-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0123.html"/>
        <reference source="CESA" ref_id="CESA-2013:0123"/>
        <reference source="CVE" ref_id="CVE-2011-4339" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4339.html"/>
        <description>ipmievd (aka the IPMI event daemon) in OpenIPMI, as used in the ipmitool package 1.8.11 in Red Hat Enterprise Linux (RHEL) 6, Debian GNU/Linux, Fedora 16, and other products uses 0666 permissions for its ipmievd.pid PID file, which allows local users to kill arbitrary processes by writing to this file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:32.117-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:12.074-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:17.329-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="OpenIPMI-libs is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:90038"/>
          <criterion comment="OpenIPMI-python is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:90255"/>
          <criterion comment="OpenIPMI-tools is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:90055"/>
          <criterion comment="OpenIPMI-gui is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:89387"/>
          <criterion comment="OpenIPMI-perl is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:90007"/>
          <criterion comment="OpenIPMI is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:89514"/>
          <criterion comment="OpenIPMI-devel is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:90266"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20280" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0771: curl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>curl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0771-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0771.html"/>
        <reference source="CESA" ref_id="CESA-2013:0771"/>
        <reference source="CVE" ref_id="CVE-2013-1944" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1944.html"/>
        <description>The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:11.143-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:11.783-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:17.006-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="curl is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:91134"/>
            <criterion comment="libcurl-devel is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:91228"/>
            <criterion comment="libcurl is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:90748"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="curl is earlier than 0:7.15.5-16.el5_9" test_ref="oval:org.mitre.oval:tst:91106"/>
            <criterion comment="curl-devel is earlier than 0:7.15.5-16.el5_9" test_ref="oval:org.mitre.oval:tst:90771"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20276" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1115: bind97 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1115-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1115.html"/>
        <reference source="CESA" ref_id="CESA-2013:1115"/>
        <reference source="CVE" ref_id="CVE-2013-4854" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4854.html"/>
        <description>The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during construction of a log message, as exploited in the wild in July 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:25.141-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:11.625-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:16.873-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="bind97-utils is earlier than 32:9.7.0-17.P2.el5_9.2" test_ref="oval:org.mitre.oval:tst:91339"/>
          <criterion comment="bind97-chroot is earlier than 32:9.7.0-17.P2.el5_9.2" test_ref="oval:org.mitre.oval:tst:91581"/>
          <criterion comment="bind97 is earlier than 32:9.7.0-17.P2.el5_9.2" test_ref="oval:org.mitre.oval:tst:91070"/>
          <criterion comment="bind97-libs is earlier than 32:9.7.0-17.P2.el5_9.2" test_ref="oval:org.mitre.oval:tst:90679"/>
          <criterion comment="bind97-devel is earlier than 32:9.7.0-17.P2.el5_9.2" test_ref="oval:org.mitre.oval:tst:91037"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20254" version="453" class="patch">
      <metadata>
        <title>RHSA-2013:0822: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0822-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0822.html"/>
        <reference source="CVE" ref_id="CVE-2013-0169" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0169.html"/>
        <reference source="CVE" ref_id="CVE-2013-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0401.html"/>
        <reference source="CVE" ref_id="CVE-2013-1488" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1488.html"/>
        <reference source="CVE" ref_id="CVE-2013-1491" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1491.html"/>
        <reference source="CVE" ref_id="CVE-2013-1537" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1537.html"/>
        <reference source="CVE" ref_id="CVE-2013-1540" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1540.html"/>
        <reference source="CVE" ref_id="CVE-2013-1557" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1557.html"/>
        <reference source="CVE" ref_id="CVE-2013-1558" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1558.html"/>
        <reference source="CVE" ref_id="CVE-2013-1563" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1563.html"/>
        <reference source="CVE" ref_id="CVE-2013-1569" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1569.html"/>
        <reference source="CVE" ref_id="CVE-2013-2383" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2383.html"/>
        <reference source="CVE" ref_id="CVE-2013-2384" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2384.html"/>
        <reference source="CVE" ref_id="CVE-2013-2394" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2394.html"/>
        <reference source="CVE" ref_id="CVE-2013-2415" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2415.html"/>
        <reference source="CVE" ref_id="CVE-2013-2416" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2416.html"/>
        <reference source="CVE" ref_id="CVE-2013-2417" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2417.html"/>
        <reference source="CVE" ref_id="CVE-2013-2418" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2418.html"/>
        <reference source="CVE" ref_id="CVE-2013-2419" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2419.html"/>
        <reference source="CVE" ref_id="CVE-2013-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2420.html"/>
        <reference source="CVE" ref_id="CVE-2013-2422" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2422.html"/>
        <reference source="CVE" ref_id="CVE-2013-2423" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2423.html"/>
        <reference source="CVE" ref_id="CVE-2013-2424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2424.html"/>
        <reference source="CVE" ref_id="CVE-2013-2426" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2426.html"/>
        <reference source="CVE" ref_id="CVE-2013-2429" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2429.html"/>
        <reference source="CVE" ref_id="CVE-2013-2430" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2430.html"/>
        <reference source="CVE" ref_id="CVE-2013-2432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2432.html"/>
        <reference source="CVE" ref_id="CVE-2013-2433" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2433.html"/>
        <reference source="CVE" ref_id="CVE-2013-2434" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2434.html"/>
        <reference source="CVE" ref_id="CVE-2013-2435" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2435.html"/>
        <reference source="CVE" ref_id="CVE-2013-2436" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2436.html"/>
        <reference source="CVE" ref_id="CVE-2013-2438" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2438.html"/>
        <reference source="CVE" ref_id="CVE-2013-2440" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2440.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2435.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:33.801-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:10.596-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:15.663-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20254 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:21.503-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:08.547-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.4.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137658"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.4.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137598"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.4.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:136863"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.4.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137553"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.4.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137834"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.4.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137326"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.4.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91005"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.4.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91076"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.4.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91184"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.4.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91162"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.4.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91211"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.4.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91236"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20250" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0132: autofs security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>autofs</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0132-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0132.html"/>
        <reference source="CESA" ref_id="CESA-2013:0132"/>
        <reference source="CVE" ref_id="CVE-2012-2697" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2697.html"/>
        <description>Unspecified vulnerability in autofs, as used in Red Hat Enterprise Linux (RHEL) 5, allows local users to cause a denial of service (autofs crash and delayed mounts) or prevent "mount expiration" via unspecified vectors related to "using an LDAP-based automount map."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:39.713-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:10.474-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:15.521-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criterion comment="autofs is earlier than 1:5.0.1-0.rc2.177.el5" test_ref="oval:org.mitre.oval:tst:89844"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20249" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0621: kernel security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0621-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0621.html"/>
        <reference source="CESA" ref_id="CESA-2013:0621"/>
        <reference source="CVE" ref_id="CVE-2013-0268" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0268.html"/>
        <reference source="CVE" ref_id="CVE-2013-0871" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0871.html"/>
        <description>Race condition in the ptrace functionality in the Linux kernel before 3.7.5 allows local users to gain privileges via a PTRACE_SETREGS ptrace system call in a crafted application, as demonstrated by ptrace_death.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:20.117-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:10.280-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:15.296-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:90419"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:90736"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:90954"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:90940"/>
          <criterion comment="kernel is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:90810"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:90364"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:90237"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:90901"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:90806"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:90827"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:90787"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:90354"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20230" version="171" class="patch">
      <metadata>
        <title>RHSA-2013:0145: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0145-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0145.html"/>
        <reference source="CESA" ref_id="CESA-2013:0145"/>
        <reference source="CVE" ref_id="CVE-2013-0744" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0744.html"/>
        <reference source="CVE" ref_id="CVE-2013-0746" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0746.html"/>
        <reference source="CVE" ref_id="CVE-2013-0748" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0748.html"/>
        <reference source="CVE" ref_id="CVE-2013-0750" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0750.html"/>
        <reference source="CVE" ref_id="CVE-2013-0753" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0753.html"/>
        <reference source="CVE" ref_id="CVE-2013-0754" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0754.html"/>
        <reference source="CVE" ref_id="CVE-2013-0758" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0758.html"/>
        <reference source="CVE" ref_id="CVE-2013-0759" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0759.html"/>
        <reference source="CVE" ref_id="CVE-2013-0762" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0762.html"/>
        <reference source="CVE" ref_id="CVE-2013-0766" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0766.html"/>
        <reference source="CVE" ref_id="CVE-2013-0767" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0767.html"/>
        <reference source="CVE" ref_id="CVE-2013-0769" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0769.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:10.494-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:09.756-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:14.390-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.12-3.el6_3" test_ref="oval:org.mitre.oval:tst:90121"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.12-3.el6.centos" test_ref="oval:org.mitre.oval:tst:91450"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.12-3.el5_9" test_ref="oval:org.mitre.oval:tst:90328"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.12-3.el5.centos" test_ref="oval:org.mitre.oval:tst:91722"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20273" version="6" class="inventory">
      <metadata>
        <title>The operating system installed on the system is Red Hat Enterprise Linux 6</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:redhat:enterprise_linux:6"/>
        <description>The operating system installed on the system is Red Hat Enterprise Linux 6.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-09T13:03:37">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2013-12-10T12:34:55.121-05:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:28686 - modified object oval:org.mitre.oval:obj:28686. regex was added to make the inventory more general." date="2013-12-13T11:11:00.085-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-30T04:00:35.434-05:00">INTERIM</status_change>
            <status_change date="2014-01-20T04:00:35.410-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20273 - new criterion was added to avoid operation in Oracle Linux system" date="2014-05-08T11:04:00.653-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-08T11:06:06.167-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:00:11.457-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Red Hat Enterprise 6 is installed" test_ref="oval:org.mitre.oval:tst:88889"/>
        <criterion negate="true" comment="Oracle Linux 6.x is installed" test_ref="oval:org.mitre.oval:tst:80772"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16337" version="5" class="inventory">
      <metadata>
        <title>The operating system installed on the system is CentOS Linux 6.x</title>
        <affected family="unix">
          <platform>CentOS Linux 6</platform>
        </affected>
        <reference ref_id="cpe:/o:centos:centos:6" source="CPE"/>
        <description>The operating system installed on the system is CentOS Linux 6.x</description>
        <oval_repository>
          <dates>
            <submitted date="2013-03-05T10:00:00.000-00:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2013-03-06T10:17:12.235-05:00">DRAFT</status_change>
            <status_change date="2013-03-25T04:00:27.566-04:00">INTERIM</status_change>
            <status_change date="2013-04-15T04:00:16.187-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16337 - new definitions (patch) for the CentOS &amp; RedHat 2012." date="2014-01-15T12:02:00.592-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2014-01-15T12:21:47.462-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:00:42.138-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Unix family" test_ref="oval:org.mitre.oval:tst:4424"/>
        <criterion comment="CentOS Linux 6.x is installed" test_ref="oval:org.mitre.oval:tst:80900"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20157" version="283" class="patch">
      <metadata>
        <title>RHSA-2013:0246: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0246-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0246.html"/>
        <reference source="CESA" ref_id="CESA-2013:0246"/>
        <reference source="CVE" ref_id="CVE-2013-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0424.html"/>
        <reference source="CVE" ref_id="CVE-2013-0425" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0425.html"/>
        <reference source="CVE" ref_id="CVE-2013-0426" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0426.html"/>
        <reference source="CVE" ref_id="CVE-2013-0427" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0427.html"/>
        <reference source="CVE" ref_id="CVE-2013-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0428.html"/>
        <reference source="CVE" ref_id="CVE-2013-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0429.html"/>
        <reference source="CVE" ref_id="CVE-2013-0432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0432.html"/>
        <reference source="CVE" ref_id="CVE-2013-0433" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0433.html"/>
        <reference source="CVE" ref_id="CVE-2013-0434" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0434.html"/>
        <reference source="CVE" ref_id="CVE-2013-0435" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0435.html"/>
        <reference source="CVE" ref_id="CVE-2013-0440" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0440.html"/>
        <reference source="CVE" ref_id="CVE-2013-0441" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0441.html"/>
        <reference source="CVE" ref_id="CVE-2013-0442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0442.html"/>
        <reference source="CVE" ref_id="CVE-2013-0443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0443.html"/>
        <reference source="CVE" ref_id="CVE-2013-0445" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0445.html"/>
        <reference source="CVE" ref_id="CVE-2013-0450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0450.html"/>
        <reference source="CVE" ref_id="CVE-2013-1475" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1475.html"/>
        <reference source="CVE" ref_id="CVE-2013-1476" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1476.html"/>
        <reference source="CVE" ref_id="CVE-2013-1478" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1478.html"/>
        <reference source="CVE" ref_id="CVE-2013-1480" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1480.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient validation of raster parameters" in awt_parseImage.c, which triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:00.458-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:08.301-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:13.047-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.33.1.11.6.el5_9" test_ref="oval:org.mitre.oval:tst:90502"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.33.1.11.6.el5_9" test_ref="oval:org.mitre.oval:tst:90254"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.33.1.11.6.el5_9" test_ref="oval:org.mitre.oval:tst:90416"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.33.1.11.6.el5_9" test_ref="oval:org.mitre.oval:tst:90466"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.33.1.11.6.el5_9" test_ref="oval:org.mitre.oval:tst:90454"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20150" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0135: gtk2 security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>gtk2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0135-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0135.html"/>
        <reference source="CESA" ref_id="CESA-2013:0135"/>
        <reference source="CVE" ref_id="CVE-2012-2370" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2370.html"/>
        <description>Multiple integer overflows in the read_bitmap_file_data function in io-xbm.c in gdk-pixbuf before 2.26.1 allow remote attackers to cause a denial of service (application crash) via a negative (1) height or (2) width in an XBM file, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:32.255-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:08.180-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:12.884-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="gtk2-devel is earlier than 0:2.10.4-29.el5" test_ref="oval:org.mitre.oval:tst:89761"/>
          <criterion comment="gtk2 is earlier than 0:2.10.4-29.el5" test_ref="oval:org.mitre.oval:tst:89976"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15802" version="7" class="inventory">
      <metadata>
        <title>The operating system installed on the system is CentOS Linux 5.x</title>
        <affected family="unix">
          <platform>CentOS Linux 5</platform>
        </affected>
        <reference ref_id="cpe:/o:centos:centos:5" source="CPE"/>
        <description>The operating system installed on the system is CentOS Linux 5.x</description>
        <oval_repository>
          <dates>
            <submitted date="2012-12-11T10:36:00.000-05:00">
              <contributor organization="MITRE">Danny Haynes</contributor>
            </submitted>
            <status_change date="2012-12-12T17:30:41.244-05:00">DRAFT</status_change>
            <status_change date="2012-12-31T04:01:31.486-05:00">INTERIM</status_change>
            <status_change date="2013-01-21T04:00:13.958-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:20137 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:38.109-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:16:16.163-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:15802 - new definitions (patch) for the CentOS &amp; RedHat 2012." date="2014-01-15T12:02:00.592-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2014-01-15T12:21:47.538-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:00:37.998-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Unix family" test_ref="oval:org.mitre.oval:tst:4424"/>
        <criterion comment="CentOS Linux 5.x is installed" test_ref="oval:org.mitre.oval:tst:80416"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11414" version="7" class="inventory">
      <metadata>
        <title>The operating system installed on the system is Red Hat Enterprise Linux 5</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:redhat:enterprise_linux:5"/>
        <description>The operating system installed on the system is Red Hat Enterprise Linux 5.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-06T12:00:00.000-06:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:29.872-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:16.744-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:00.824-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11414 - Updated CPE reference, updated regular expression" date="2011-02-17T13:31:00.837-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-02-17T13:32:08.284-05:00">INTERIM</status_change>
            <status_change date="2011-03-07T04:00:03.934-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:11314 - Corrected - right version for brlapi and brlapi-devel as specified by RHSA-2010:0181-5" date="2013-03-18T12:26:00.995-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-18T12:31:15.870-04:00">INTERIM</status_change>
            <status_change date="2013-04-08T04:00:06.890-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Red Hat Enterprise 5 is installed" test_ref="oval:org.mitre.oval:tst:3846"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <rpminfo_test id="oval:org.mitre.oval:tst:141115" version="1" comment="ntp is earlier than 0:4.2.2p1-9.el5.centos.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14371"/>
      <state state_ref="oval:org.mitre.oval:ste:38921"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141024" version="1" comment="ntp is earlier than 0:4.2.2p1-9.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14371"/>
      <state state_ref="oval:org.mitre.oval:ste:39287"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141160" version="1" comment="kernel-debug is earlier than 0:2.6.18-128.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:39557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141042" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:39557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140988" version="1" comment="kernel-devel is earlier than 0:2.6.18-128.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:39557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140975" version="1" comment="kernel-headers is earlier than 0:2.6.18-128.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:39557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140945" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:39557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140924" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:39557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140921" version="1" comment="kernel-PAE is earlier than 0:2.6.18-128.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:39557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140909" version="1" comment="kernel-doc is earlier than 0:2.6.18-128.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:39557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140816" version="1" comment="kernel is earlier than 0:2.6.18-128.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:39557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140426" version="1" comment="kernel-xen is earlier than 0:2.6.18-128.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:39557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141077" version="1" comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:39118"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141044" version="1" comment="firefox is earlier than 0:3.0.11-4.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39433"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140998" version="1" comment="xulrunner is earlier than 0:1.9.0.11-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:39118"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140919" version="1" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15048"/>
      <state state_ref="oval:org.mitre.oval:ste:39118"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140856" version="1" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15048"/>
      <state state_ref="oval:org.mitre.oval:ste:39068"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140819" version="1" comment="firefox is earlier than 0:3.0.11-2.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:38785"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140702" version="1" comment="xulrunner is earlier than 0:1.9.0.11-3.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:39068"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140701" version="1" comment="firefox is earlier than 0:3.0.11-2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39439"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140443" version="1" comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:39068"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139942" version="1" comment="device-mapper-multipath is earlier than 0:0.4.5-31.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15272"/>
      <state state_ref="oval:org.mitre.oval:ste:39055"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139876" version="1" comment="device-mapper-multipath is earlier than 0:0.4.7-23.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15272"/>
      <state state_ref="oval:org.mitre.oval:ste:38566"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139382" version="1" comment="kpartx is earlier than 0:0.4.7-23.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15125"/>
      <state state_ref="oval:org.mitre.oval:ste:38566"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139764" version="1" comment="dstat is earlier than 0:0.6.6-3.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14661"/>
      <state state_ref="oval:org.mitre.oval:ste:39186"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140385" version="1" comment="firefox is earlier than 0:3.0.7-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39233"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140359" version="1" comment="xulrunner-devel is earlier than 0:1.9.0.7-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:39405"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140357" version="1" comment="xulrunner is earlier than 0:1.9.0.7-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:39405"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140353" version="1" comment="firefox is earlier than 0:3.0.7-1.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39139"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140183" version="1" comment="firefox is earlier than 0:3.0.7-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39132"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140178" version="1" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15048"/>
      <state state_ref="oval:org.mitre.oval:ste:39405"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140307" version="1" comment="libwmf is earlier than 0:0.2.8.3-5.8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14677"/>
      <state state_ref="oval:org.mitre.oval:ste:39172"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140274" version="1" comment="libwmf-devel is earlier than 0:0.2.8.3-5.8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14833"/>
      <state state_ref="oval:org.mitre.oval:ste:39172"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140042" version="1" comment="libwmf-devel is earlier than 0:0.2.8.4-10.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14833"/>
      <state state_ref="oval:org.mitre.oval:ste:39369"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139931" version="1" comment="libwmf is earlier than 0:0.2.8.4-10.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14677"/>
      <state state_ref="oval:org.mitre.oval:ste:39369"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140731" version="1" comment="fetchmail is earlier than 0:6.2.0-3.el3.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14633"/>
      <state state_ref="oval:org.mitre.oval:ste:39106"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140541" version="1" comment="fetchmail is earlier than 0:6.2.5-6.0.1.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14633"/>
      <state state_ref="oval:org.mitre.oval:ste:38520"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140338" version="1" comment="fetchmail is earlier than 0:6.3.6-1.1.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14633"/>
      <state state_ref="oval:org.mitre.oval:ste:39003"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140526" version="1" comment="squirrelmail is earlier than 0:1.4.8-5.el5.centos.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14331"/>
      <state state_ref="oval:org.mitre.oval:ste:38922"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140516" version="1" comment="squirrelmail is earlier than 0:1.4.8-5.el5_2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14331"/>
      <state state_ref="oval:org.mitre.oval:ste:39234"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140185" version="1" comment="squirrelmail is earlier than 0:1.4.8-5.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14331"/>
      <state state_ref="oval:org.mitre.oval:ste:39283"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139889" version="1" comment="squirrelmail is earlier than 0:1.4.8-8.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14331"/>
      <state state_ref="oval:org.mitre.oval:ste:39275"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140462" version="1" comment="libsoup is earlier than 0:2.2.98-2.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15103"/>
      <state state_ref="oval:org.mitre.oval:ste:38958"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140436" version="1" comment="evolution28-libsoup-devel is earlier than 0:2.2.98-5.el4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14798"/>
      <state state_ref="oval:org.mitre.oval:ste:39315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140412" version="1" comment="libsoup-devel is earlier than 0:2.2.1-4.el4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15129"/>
      <state state_ref="oval:org.mitre.oval:ste:39204"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140392" version="1" comment="libsoup-devel is earlier than 0:2.2.98-2.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15129"/>
      <state state_ref="oval:org.mitre.oval:ste:38958"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140243" version="1" comment="evolution28-libsoup is earlier than 0:2.2.98-5.el4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14951"/>
      <state state_ref="oval:org.mitre.oval:ste:39315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140238" version="1" comment="libsoup is earlier than 0:2.2.1-4.el4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15103"/>
      <state state_ref="oval:org.mitre.oval:ste:39204"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140674" version="1" comment="nfs-utils is earlier than 1:1.0.9-42.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14333"/>
      <state state_ref="oval:org.mitre.oval:ste:38699"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140445" version="1" comment="vnc-server is earlier than 0:4.0-12.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14330"/>
      <state state_ref="oval:org.mitre.oval:ste:38935"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140408" version="1" comment="vnc is earlier than 0:4.0-0.beta4.1.8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15059"/>
      <state state_ref="oval:org.mitre.oval:ste:39258"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140351" version="1" comment="vnc-server is earlier than 0:4.1.2-14.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14330"/>
      <state state_ref="oval:org.mitre.oval:ste:39347"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140288" version="1" comment="vnc is earlier than 0:4.1.2-14.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15059"/>
      <state state_ref="oval:org.mitre.oval:ste:39347"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140140" version="1" comment="vnc-server is earlier than 0:4.0-0.beta4.1.8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14330"/>
      <state state_ref="oval:org.mitre.oval:ste:39258"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139841" version="1" comment="vnc is earlier than 0:4.0-12.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15059"/>
      <state state_ref="oval:org.mitre.oval:ste:38935"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140215" version="1" comment="kdelibs is earlier than 6:3.5.4-25.el5.centos.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13933"/>
      <state state_ref="oval:org.mitre.oval:ste:39243"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140212" version="1" comment="kdelibs-apidocs is earlier than 6:3.5.4-25.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15138"/>
      <state state_ref="oval:org.mitre.oval:ste:38642"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140188" version="1" comment="kdelibs-devel is earlier than 6:3.3.1-17.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14126"/>
      <state state_ref="oval:org.mitre.oval:ste:39074"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140121" version="1" comment="kdelibs is earlier than 6:3.5.4-25.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13933"/>
      <state state_ref="oval:org.mitre.oval:ste:38642"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140119" version="1" comment="kdelibs-apidocs is earlier than 6:3.5.4-25.el5.centos.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15138"/>
      <state state_ref="oval:org.mitre.oval:ste:39243"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140061" version="1" comment="kdelibs-devel is earlier than 6:3.5.4-25.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14126"/>
      <state state_ref="oval:org.mitre.oval:ste:38642"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139912" version="1" comment="kdelibs-devel is earlier than 6:3.5.4-25.el5.centos.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14126"/>
      <state state_ref="oval:org.mitre.oval:ste:39243"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139744" version="1" comment="kdelibs is earlier than 6:3.3.1-17.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13933"/>
      <state state_ref="oval:org.mitre.oval:ste:39074"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140513" version="1" comment="dnsmasq is earlier than 0:2.45-1.1.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14690"/>
      <state state_ref="oval:org.mitre.oval:ste:39293"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140383" version="1" comment="ecryptfs-utils-devel is earlier than 0:75-5.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15215"/>
      <state state_ref="oval:org.mitre.oval:ste:39345"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140283" version="1" comment="ecryptfs-utils-gui is earlier than 0:75-5.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15070"/>
      <state state_ref="oval:org.mitre.oval:ste:39345"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140147" version="1" comment="ecryptfs-utils is earlier than 0:75-5.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15120"/>
      <state state_ref="oval:org.mitre.oval:ste:39345"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140586" version="1" comment="kernel-debug is earlier than 0:2.6.18-92.1.22.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:39049"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140487" version="1" comment="kernel is earlier than 0:2.6.18-92.1.22.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:39049"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140482" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.22.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:39049"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140455" version="1" comment="kernel-PAE is earlier than 0:2.6.18-92.1.22.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:39049"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140451" version="1" comment="kernel-xen is earlier than 0:2.6.18-92.1.22.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:39049"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140171" version="1" comment="kernel-devel is earlier than 0:2.6.18-92.1.22.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:39049"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140086" version="1" comment="kernel-doc is earlier than 0:2.6.18-92.1.22.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:39049"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140019" version="1" comment="kernel-headers is earlier than 0:2.6.18-92.1.22.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:39049"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139690" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.22.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:39049"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139667" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.22.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:39049"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140866" version="1" comment="openssh-askpass is earlier than 0:4.3p2-36.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14577"/>
      <state state_ref="oval:org.mitre.oval:ste:39158"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140749" version="1" comment="openssh-clients is earlier than 0:4.3p2-36.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14409"/>
      <state state_ref="oval:org.mitre.oval:ste:39158"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140711" version="1" comment="openssh is earlier than 0:4.3p2-36.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14581"/>
      <state state_ref="oval:org.mitre.oval:ste:39158"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140352" version="1" comment="openssh-server is earlier than 0:4.3p2-36.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14544"/>
      <state state_ref="oval:org.mitre.oval:ste:39158"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140268" version="1" comment="expat-devel is earlier than 0:1.95.5-6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15283"/>
      <state state_ref="oval:org.mitre.oval:ste:38926"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140240" version="1" comment="expat-devel is earlier than 0:1.95.8-8.3.el5_4.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15283"/>
      <state state_ref="oval:org.mitre.oval:ste:38391"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140152" version="1" comment="expat-devel is earlier than 0:1.95.7-4.el4_8.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15283"/>
      <state state_ref="oval:org.mitre.oval:ste:39133"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140080" version="1" comment="expat is earlier than 0:1.95.7-4.el4_8.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14999"/>
      <state state_ref="oval:org.mitre.oval:ste:39133"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139982" version="1" comment="expat is earlier than 0:1.95.5-6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14999"/>
      <state state_ref="oval:org.mitre.oval:ste:38926"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139271" version="1" comment="expat is earlier than 0:1.95.8-8.3.el5_4.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14999"/>
      <state state_ref="oval:org.mitre.oval:ste:38391"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140358" version="1" comment="php-mbstring is earlier than 0:5.1.6-23.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13746"/>
      <state state_ref="oval:org.mitre.oval:ste:39375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140339" version="1" comment="php-dba is earlier than 0:5.1.6-23.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14512"/>
      <state state_ref="oval:org.mitre.oval:ste:39375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140329" version="1" comment="php-mysql is earlier than 0:5.1.6-23.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14080"/>
      <state state_ref="oval:org.mitre.oval:ste:39375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140323" version="1" comment="php-xml is earlier than 0:5.1.6-23.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14560"/>
      <state state_ref="oval:org.mitre.oval:ste:39375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140278" version="1" comment="php-xmlrpc is earlier than 0:5.1.6-23.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14445"/>
      <state state_ref="oval:org.mitre.oval:ste:39375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140227" version="1" comment="php-ldap is earlier than 0:5.1.6-23.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14375"/>
      <state state_ref="oval:org.mitre.oval:ste:39375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140198" version="1" comment="php-common is earlier than 0:5.1.6-23.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14841"/>
      <state state_ref="oval:org.mitre.oval:ste:39375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140161" version="1" comment="php-bcmath is earlier than 0:5.1.6-23.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14639"/>
      <state state_ref="oval:org.mitre.oval:ste:39375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140154" version="1" comment="php-ncurses is earlier than 0:5.1.6-23.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14227"/>
      <state state_ref="oval:org.mitre.oval:ste:39375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140129" version="1" comment="php-snmp is earlier than 0:5.1.6-23.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14508"/>
      <state state_ref="oval:org.mitre.oval:ste:39375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140127" version="1" comment="php-odbc is earlier than 0:5.1.6-23.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14183"/>
      <state state_ref="oval:org.mitre.oval:ste:39375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140111" version="1" comment="php-imap is earlier than 0:5.1.6-23.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14250"/>
      <state state_ref="oval:org.mitre.oval:ste:39375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140079" version="1" comment="php-devel is earlier than 0:5.1.6-23.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13492"/>
      <state state_ref="oval:org.mitre.oval:ste:39375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140066" version="1" comment="php is earlier than 0:5.1.6-23.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14294"/>
      <state state_ref="oval:org.mitre.oval:ste:39375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139987" version="1" comment="php-soap is earlier than 0:5.1.6-23.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14366"/>
      <state state_ref="oval:org.mitre.oval:ste:39375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139852" version="1" comment="php-pgsql is earlier than 0:5.1.6-23.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14148"/>
      <state state_ref="oval:org.mitre.oval:ste:39375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139761" version="1" comment="php-gd is earlier than 0:5.1.6-23.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14335"/>
      <state state_ref="oval:org.mitre.oval:ste:39375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139468" version="1" comment="php-cli is earlier than 0:5.1.6-23.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14922"/>
      <state state_ref="oval:org.mitre.oval:ste:39375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139406" version="1" comment="php-pdo is earlier than 0:5.1.6-23.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14154"/>
      <state state_ref="oval:org.mitre.oval:ste:39375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140498" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-128.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:39269"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140466" version="1" comment="kernel-debug is earlier than 0:2.6.18-128.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:39269"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140411" version="1" comment="kernel is earlier than 0:2.6.18-128.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:39269"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140403" version="1" comment="kernel-headers is earlier than 0:2.6.18-128.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:39269"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140312" version="1" comment="kernel-xen is earlier than 0:2.6.18-128.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:39269"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140249" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-128.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:39269"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140242" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:39269"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140236" version="1" comment="kernel-devel is earlier than 0:2.6.18-128.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:39269"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140200" version="1" comment="kernel-PAE is earlier than 0:2.6.18-128.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:39269"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140143" version="1" comment="kernel-doc is earlier than 0:2.6.18-128.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:39269"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140229" version="1" comment="xulrunner-devel is earlier than 0:1.9.0.16-2.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:38992"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140209" version="1" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.16-2.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15048"/>
      <state state_ref="oval:org.mitre.oval:ste:38992"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140068" version="1" comment="firefox is earlier than 0:3.0.16-1.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39203"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140040" version="1" comment="xulrunner is earlier than 0:1.9.0.16-2.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:38992"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140035" version="1" comment="firefox is earlier than 0:3.0.16-4.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39230"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139751" version="1" comment="firefox is earlier than 0:3.0.16-1.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140790" version="1" comment="xen-libs is earlier than 0:3.0.3-94.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14810"/>
      <state state_ref="oval:org.mitre.oval:ste:39341"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140783" version="1" comment="xen-devel is earlier than 0:3.0.3-94.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14567"/>
      <state state_ref="oval:org.mitre.oval:ste:39341"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140576" version="1" comment="xen is earlier than 0:3.0.3-94.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14646"/>
      <state state_ref="oval:org.mitre.oval:ste:39341"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141047" version="1" comment="squirrelmail is earlier than 0:1.4.8-5.el5.centos.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14331"/>
      <state state_ref="oval:org.mitre.oval:ste:38867"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141022" version="1" comment="squirrelmail is earlier than 0:1.4.8-5.el5_3.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14331"/>
      <state state_ref="oval:org.mitre.oval:ste:39141"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140925" version="1" comment="squirrelmail is earlier than 0:1.4.8-13.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14331"/>
      <state state_ref="oval:org.mitre.oval:ste:39390"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140607" version="1" comment="squirrelmail is earlier than 0:1.4.8-5.el4_8.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14331"/>
      <state state_ref="oval:org.mitre.oval:ste:39493"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140834" version="1" comment="xulrunner is earlier than 0:1.9.0.14-1.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:39359"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140728" version="1" comment="nspr-devel is earlier than 0:4.7.5-1.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15145"/>
      <state state_ref="oval:org.mitre.oval:ste:39360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140668" version="1" comment="xulrunner-devel is earlier than 0:1.9.0.14-1.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:39359"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140642" version="1" comment="firefox is earlier than 0:3.0.14-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39205"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140595" version="1" comment="firefox is earlier than 0:3.0.14-1.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39045"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140504" version="1" comment="firefox is earlier than 0:3.0.14-1.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:38730"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140461" version="1" comment="nspr-devel is earlier than 0:4.7.5-1.el4_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15145"/>
      <state state_ref="oval:org.mitre.oval:ste:38996"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140340" version="1" comment="nspr is earlier than 0:4.7.5-1.el4_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14745"/>
      <state state_ref="oval:org.mitre.oval:ste:38996"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139862" version="1" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.14-1.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15048"/>
      <state state_ref="oval:org.mitre.oval:ste:39359"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139833" version="1" comment="nspr is earlier than 0:4.7.5-1.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14745"/>
      <state state_ref="oval:org.mitre.oval:ste:39360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140785" version="1" comment="freeradius-postgresql is earlier than 0:1.1.3-1.5.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14475"/>
      <state state_ref="oval:org.mitre.oval:ste:39322"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140646" version="1" comment="freeradius-mysql is earlier than 0:1.1.3-1.5.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14691"/>
      <state state_ref="oval:org.mitre.oval:ste:39322"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140537" version="1" comment="freeradius is earlier than 0:1.1.3-1.5.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14420"/>
      <state state_ref="oval:org.mitre.oval:ste:39322"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140356" version="1" comment="freeradius-unixODBC is earlier than 0:1.1.3-1.5.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13705"/>
      <state state_ref="oval:org.mitre.oval:ste:39322"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140817" version="1" comment="xmlsec1 is earlier than 0:1.2.9-8.1.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15214"/>
      <state state_ref="oval:org.mitre.oval:ste:39031"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140808" version="1" comment="xmlsec1-openssl is earlier than 0:1.2.9-8.1.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15197"/>
      <state state_ref="oval:org.mitre.oval:ste:39031"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140781" version="1" comment="xmlsec1-gnutls-devel is earlier than 0:1.2.9-8.1.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15241"/>
      <state state_ref="oval:org.mitre.oval:ste:39031"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140757" version="1" comment="xmlsec1-nss-devel is earlier than 0:1.2.9-8.1.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15222"/>
      <state state_ref="oval:org.mitre.oval:ste:39031"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140725" version="1" comment="xmlsec1-openssl-devel is earlier than 0:1.2.6-3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15175"/>
      <state state_ref="oval:org.mitre.oval:ste:39344"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140664" version="1" comment="xmlsec1-devel is earlier than 0:1.2.9-8.1.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15290"/>
      <state state_ref="oval:org.mitre.oval:ste:39031"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140647" version="1" comment="xmlsec1-devel is earlier than 0:1.2.6-3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15290"/>
      <state state_ref="oval:org.mitre.oval:ste:39344"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140592" version="1" comment="xmlsec1-nss is earlier than 0:1.2.9-8.1.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14874"/>
      <state state_ref="oval:org.mitre.oval:ste:39031"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140571" version="1" comment="xmlsec1-openssl-devel is earlier than 0:1.2.9-8.1.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15175"/>
      <state state_ref="oval:org.mitre.oval:ste:39031"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140559" version="1" comment="xmlsec1-openssl is earlier than 0:1.2.6-3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15197"/>
      <state state_ref="oval:org.mitre.oval:ste:39344"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140194" version="1" comment="xmlsec1 is earlier than 0:1.2.6-3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15214"/>
      <state state_ref="oval:org.mitre.oval:ste:39344"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139883" version="1" comment="xmlsec1-gnutls is earlier than 0:1.2.9-8.1.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15043"/>
      <state state_ref="oval:org.mitre.oval:ste:39031"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140365" version="1" comment="gstreamer-plugins-base is earlier than 0:0.10.20-3.0.1.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14634"/>
      <state state_ref="oval:org.mitre.oval:ste:39011"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140069" version="1" comment="gstreamer-plugins-base-devel is earlier than 0:0.10.20-3.0.1.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14467"/>
      <state state_ref="oval:org.mitre.oval:ste:39011"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140256" version="1" comment="httpd is earlier than 0:2.0.46-77.ent" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:39167"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140246" version="1" comment="mod_ssl is earlier than 0:2.2.3-31.el5.centos.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:38751"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140233" version="1" comment="mod_ssl is earlier than 0:2.2.3-31.el5_4.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:39146"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140230" version="1" comment="httpd-manual is earlier than 0:2.2.3-31.el5.centos.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:38751"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140205" version="1" comment="httpd is earlier than 0:2.2.3-31.el5_4.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:39146"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140144" version="1" comment="httpd-manual is earlier than 0:2.2.3-31.el5_4.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:39146"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140142" version="1" comment="httpd-devel is earlier than 0:2.2.3-31.el5_4.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14256"/>
      <state state_ref="oval:org.mitre.oval:ste:39146"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140131" version="1" comment="httpd-devel is earlier than 0:2.0.46-77.ent" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14256"/>
      <state state_ref="oval:org.mitre.oval:ste:39167"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139959" version="1" comment="httpd-devel is earlier than 0:2.2.3-31.el5.centos.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14256"/>
      <state state_ref="oval:org.mitre.oval:ste:38751"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139927" version="1" comment="httpd is earlier than 0:2.2.3-31.el5.centos.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:38751"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139723" version="1" comment="mod_ssl is earlier than 0:2.0.46-77.ent" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:39167"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140296" version="1" comment="dovecot is earlier than 0:1.0.7-7.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3572"/>
      <state state_ref="oval:org.mitre.oval:ste:38422"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141073" version="1" comment="gstreamer-plugins-good-devel is earlier than 0:0.10.9-1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14946"/>
      <state state_ref="oval:org.mitre.oval:ste:39301"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140782" version="1" comment="gstreamer-plugins-good is earlier than 0:0.10.9-1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15182"/>
      <state state_ref="oval:org.mitre.oval:ste:39301"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140739" version="1" comment="cups-libs is earlier than 1:1.3.7-11.el5_4.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14195"/>
      <state state_ref="oval:org.mitre.oval:ste:39245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140676" version="1" comment="cups is earlier than 1:1.3.7-11.el5_4.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14199"/>
      <state state_ref="oval:org.mitre.oval:ste:39245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140610" version="1" comment="cups-lpd is earlier than 1:1.3.7-11.el5_4.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14688"/>
      <state state_ref="oval:org.mitre.oval:ste:39245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140070" version="1" comment="cups-devel is earlier than 1:1.3.7-11.el5_4.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14076"/>
      <state state_ref="oval:org.mitre.oval:ste:39245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140722" version="1" comment="tog-pegasus is earlier than 2:2.7.0-2.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14965"/>
      <state state_ref="oval:org.mitre.oval:ste:38988"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140289" version="1" comment="tog-pegasus-devel is earlier than 2:2.7.0-2.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15071"/>
      <state state_ref="oval:org.mitre.oval:ste:38988"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140734" version="1" comment="libxml2-devel is earlier than 0:2.5.10-14" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:38406"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140712" version="1" comment="libxml2 is earlier than 0:2.6.26-2.1.2.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:39310"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140707" version="1" comment="libxml2-python is earlier than 0:2.6.26-2.1.2.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:39310"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140671" version="1" comment="libxml2-devel is earlier than 0:2.6.16-12.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:39021"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140507" version="1" comment="libxml2 is earlier than 0:2.5.10-14" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:38406"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140444" version="1" comment="libxml2-python is earlier than 0:2.6.16-12.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:39021"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140442" version="1" comment="libxml2 is earlier than 0:2.6.16-12.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:39021"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140330" version="1" comment="libxml2-python is earlier than 0:2.5.10-14" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:38406"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139787" version="1" comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:39310"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141054" version="1" comment="kdelibs is earlier than 6:3.5.4-22.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13933"/>
      <state state_ref="oval:org.mitre.oval:ste:39319"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140980" version="1" comment="kdelibs-apidocs is earlier than 6:3.5.4-22.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15138"/>
      <state state_ref="oval:org.mitre.oval:ste:39319"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140970" version="1" comment="kdelibs-devel is earlier than 6:3.5.4-22.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14126"/>
      <state state_ref="oval:org.mitre.oval:ste:39319"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140955" version="1" comment="kdelibs is earlier than 6:3.3.1-14.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13933"/>
      <state state_ref="oval:org.mitre.oval:ste:39317"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140922" version="1" comment="kdelibs is earlier than 6:3.5.4-22.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13933"/>
      <state state_ref="oval:org.mitre.oval:ste:38629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140906" version="1" comment="kdelibs-apidocs is earlier than 6:3.5.4-22.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15138"/>
      <state state_ref="oval:org.mitre.oval:ste:38629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140547" version="1" comment="kdelibs-devel is earlier than 6:3.3.1-14.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14126"/>
      <state state_ref="oval:org.mitre.oval:ste:39317"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140490" version="1" comment="kdelibs-devel is earlier than 6:3.5.4-22.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14126"/>
      <state state_ref="oval:org.mitre.oval:ste:38629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140585" version="1" comment="python-lcms is earlier than 0:1.15-1.2.2.el5_2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14958"/>
      <state state_ref="oval:org.mitre.oval:ste:39098"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140534" version="1" comment="lcms-devel is earlier than 0:1.15-1.2.2.el5_2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14904"/>
      <state state_ref="oval:org.mitre.oval:ste:39098"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140163" version="1" comment="lcms is earlier than 0:1.15-1.2.2.el5_2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15079"/>
      <state state_ref="oval:org.mitre.oval:ste:39098"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141065" version="1" comment="apr-util is earlier than 0:0.9.4-22.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14992"/>
      <state state_ref="oval:org.mitre.oval:ste:38809"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140961" version="1" comment="apr-util-devel is earlier than 0:1.2.7-7.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15236"/>
      <state state_ref="oval:org.mitre.oval:ste:39508"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140901" version="1" comment="apr-util is earlier than 0:1.2.7-7.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14992"/>
      <state state_ref="oval:org.mitre.oval:ste:39508"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140751" version="1" comment="apr-util-devel is earlier than 0:0.9.4-22.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15236"/>
      <state state_ref="oval:org.mitre.oval:ste:38809"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140345" version="1" comment="apr-util-docs is earlier than 0:1.2.7-7.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15199"/>
      <state state_ref="oval:org.mitre.oval:ste:39508"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140849" version="1" comment="python is earlier than 0:2.4.3-24.el5_3.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14556"/>
      <state state_ref="oval:org.mitre.oval:ste:39442"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140670" version="1" comment="tkinter is earlier than 0:2.4.3-24.el5_3.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14092"/>
      <state state_ref="oval:org.mitre.oval:ste:39442"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140390" version="1" comment="python-tools is earlier than 0:2.4.3-24.el5_3.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14208"/>
      <state state_ref="oval:org.mitre.oval:ste:39442"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140279" version="1" comment="python-devel is earlier than 0:2.4.3-24.el5_3.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14166"/>
      <state state_ref="oval:org.mitre.oval:ste:39442"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140774" version="1" comment="httpd-manual is earlier than 0:2.2.3-11.el5_2.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:39176"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140761" version="1" comment="httpd-manual is earlier than 0:2.2.3-11.el5.centos.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:38749"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140744" version="1" comment="httpd-manual is earlier than 0:2.0.52-41.ent.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:39289"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140741" version="1" comment="httpd-devel is earlier than 0:2.0.46-71.ent" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14256"/>
      <state state_ref="oval:org.mitre.oval:ste:39353"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140735" version="1" comment="httpd-devel is earlier than 0:2.2.3-11.el5_2.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14256"/>
      <state state_ref="oval:org.mitre.oval:ste:39176"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140662" version="1" comment="mod_ssl is earlier than 0:2.0.52-41.ent.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:39289"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140633" version="1" comment="httpd is earlier than 0:2.2.3-11.el5.centos.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:38749"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140630" version="1" comment="mod_ssl is earlier than 0:2.2.3-11.el5.centos.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:38749"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140593" version="1" comment="mod_ssl is earlier than 0:2.0.46-71.ent" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:39353"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140591" version="1" comment="mod_ssl is earlier than 0:2.2.3-11.el5_2.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:39176"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140553" version="1" comment="httpd is earlier than 0:2.0.52-41.ent.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:39289"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140397" version="1" comment="httpd is earlier than 0:2.2.3-11.el5_2.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:39176"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140396" version="1" comment="httpd-devel is earlier than 0:2.2.3-11.el5.centos.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14256"/>
      <state state_ref="oval:org.mitre.oval:ste:38749"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140328" version="1" comment="httpd-devel is earlier than 0:2.0.52-41.ent.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14256"/>
      <state state_ref="oval:org.mitre.oval:ste:39289"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140222" version="1" comment="httpd-suexec is earlier than 0:2.0.52-41.ent.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14611"/>
      <state state_ref="oval:org.mitre.oval:ste:39289"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140159" version="1" comment="httpd is earlier than 0:2.0.46-71.ent" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:39353"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140582" version="1" comment="dbus-x11 is earlier than 0:1.0.0-7.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14132"/>
      <state state_ref="oval:org.mitre.oval:ste:38654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140162" version="1" comment="dbus-devel is earlier than 0:1.0.0-7.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14425"/>
      <state state_ref="oval:org.mitre.oval:ste:38654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140060" version="1" comment="dbus is earlier than 0:1.0.0-7.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14213"/>
      <state state_ref="oval:org.mitre.oval:ste:38654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140120" version="1" comment="giflib is earlier than 0:4.1.3-7.1.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15258"/>
      <state state_ref="oval:org.mitre.oval:ste:38900"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140026" version="1" comment="giflib-devel is earlier than 0:4.1.3-7.1.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15149"/>
      <state state_ref="oval:org.mitre.oval:ste:38900"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139609" version="1" comment="giflib-utils is earlier than 0:4.1.3-7.1.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15115"/>
      <state state_ref="oval:org.mitre.oval:ste:38900"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140220" version="1" comment="libtool is earlier than 0:1.5.22-7.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15211"/>
      <state state_ref="oval:org.mitre.oval:ste:39260"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140149" version="1" comment="libtool is earlier than 0:1.4.3-7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15211"/>
      <state state_ref="oval:org.mitre.oval:ste:39059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140110" version="1" comment="libtool-libs is earlier than 0:1.4.3-7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15029"/>
      <state state_ref="oval:org.mitre.oval:ste:39059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140027" version="1" comment="libtool-ltdl is earlier than 0:1.5.22-7.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15285"/>
      <state state_ref="oval:org.mitre.oval:ste:39260"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139847" version="1" comment="libtool-libs is earlier than 0:1.5.6-5.el4_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15029"/>
      <state state_ref="oval:org.mitre.oval:ste:39226"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139736" version="1" comment="libtool-ltdl-devel is earlier than 0:1.5.22-7.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14788"/>
      <state state_ref="oval:org.mitre.oval:ste:39260"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139520" version="1" comment="libtool is earlier than 0:1.5.6-5.el4_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15211"/>
      <state state_ref="oval:org.mitre.oval:ste:39226"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140878" version="1" comment="gnutls-devel is earlier than 0:1.4.1-3.el5_3.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14558"/>
      <state state_ref="oval:org.mitre.oval:ste:39096"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140864" version="1" comment="gnutls is earlier than 0:1.0.20-4.el4_8.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14386"/>
      <state state_ref="oval:org.mitre.oval:ste:39177"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140842" version="1" comment="gnutls-devel is earlier than 0:1.0.20-4.el4_8.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14558"/>
      <state state_ref="oval:org.mitre.oval:ste:39177"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140510" version="1" comment="gnutls-utils is earlier than 0:1.4.1-3.el5_3.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15003"/>
      <state state_ref="oval:org.mitre.oval:ste:39096"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140234" version="1" comment="gnutls is earlier than 0:1.4.1-3.el5_3.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14386"/>
      <state state_ref="oval:org.mitre.oval:ste:39096"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140367" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-0.30.b09.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:39085"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140337" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-0.30.b09.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:39085"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140304" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-0.30.b09.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:39085"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139843" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-0.30.b09.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:39085"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139386" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-0.30.b09.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:39085"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140299" version="1" comment="ghostscript is earlier than 0:8.15.2-9.4.el5_3.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14541"/>
      <state state_ref="oval:org.mitre.oval:ste:39150"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140267" version="1" comment="ghostscript-devel is earlier than 0:8.15.2-9.4.el5_3.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14524"/>
      <state state_ref="oval:org.mitre.oval:ste:39150"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139829" version="1" comment="ghostscript-gtk is earlier than 0:8.15.2-9.4.el5_3.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14614"/>
      <state state_ref="oval:org.mitre.oval:ste:39150"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140754" version="1" comment="wget is earlier than 0:1.10.2-0.30E.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14591"/>
      <state state_ref="oval:org.mitre.oval:ste:39337"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140710" version="1" comment="wget is earlier than 0:1.10.2-1.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14591"/>
      <state state_ref="oval:org.mitre.oval:ste:38420"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140459" version="1" comment="wget is earlier than 0:1.11.4-2.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14591"/>
      <state state_ref="oval:org.mitre.oval:ste:39362"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140706" version="1" comment="openssh-askpass is earlier than 0:4.3p2-36.el5_4.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14577"/>
      <state state_ref="oval:org.mitre.oval:ste:39277"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140587" version="1" comment="openssh is earlier than 0:4.3p2-36.el5_4.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14581"/>
      <state state_ref="oval:org.mitre.oval:ste:39277"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140556" version="1" comment="openssh-clients is earlier than 0:4.3p2-36.el5_4.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14409"/>
      <state state_ref="oval:org.mitre.oval:ste:39277"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140527" version="1" comment="openssh-server is earlier than 0:4.3p2-36.el5_4.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14544"/>
      <state state_ref="oval:org.mitre.oval:ste:39277"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140693" version="1" comment="neon-devel is earlier than 0:0.25.5-10.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15061"/>
      <state state_ref="oval:org.mitre.oval:ste:39191"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140645" version="1" comment="neon-devel is earlier than 0:0.24.7-4.el4_8.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15061"/>
      <state state_ref="oval:org.mitre.oval:ste:39009"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140540" version="1" comment="neon is earlier than 0:0.24.7-4.el4_8.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14799"/>
      <state state_ref="oval:org.mitre.oval:ste:39009"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140446" version="1" comment="neon is earlier than 0:0.25.5-10.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14799"/>
      <state state_ref="oval:org.mitre.oval:ste:39191"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140772" version="1" comment="kernel-devel is earlier than 0:2.6.18-164.6.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:39190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140694" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-164.6.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:39190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140663" version="1" comment="kernel-doc is earlier than 0:2.6.18-164.6.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:39190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140627" version="1" comment="kernel-headers is earlier than 0:2.6.18-164.6.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:39190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140583" version="1" comment="kernel-debug is earlier than 0:2.6.18-164.6.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:39190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140472" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-164.6.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:39190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140327" version="1" comment="kernel-PAE is earlier than 0:2.6.18-164.6.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:39190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140318" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-164.6.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:39190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140226" version="1" comment="kernel is earlier than 0:2.6.18-164.6.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:39190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139798" version="1" comment="kernel-xen is earlier than 0:2.6.18-164.6.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:39190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140302" version="1" comment="xulrunner-devel is earlier than 0:1.9.0.9-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:39333"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140223" version="1" comment="firefox is earlier than 0:3.0.9-1.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39219"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140175" version="1" comment="firefox is earlier than 0:3.0.9-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39166"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140158" version="1" comment="xulrunner is earlier than 0:1.9.0.9-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:39333"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140155" version="1" comment="firefox is earlier than 0:3.0.9-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39058"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140074" version="1" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.9-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15048"/>
      <state state_ref="oval:org.mitre.oval:ste:39333"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139946" version="1" comment="ntp is earlier than 0:4.2.0.a.20040617-8.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14371"/>
      <state state_ref="oval:org.mitre.oval:ste:38760"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139902" version="1" comment="ntp is earlier than 0:4.2.2p1-9.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14371"/>
      <state state_ref="oval:org.mitre.oval:ste:39090"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139265" version="1" comment="ntp is earlier than 0:4.2.2p1-9.el5.centos.2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14371"/>
      <state state_ref="oval:org.mitre.oval:ste:38966"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140759" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:39082"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140743" version="1" comment="kernel-xen is earlier than 0:2.6.18-92.1.18.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:39338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140720" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.18.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:39338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140703" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.18.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:39338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140688" version="1" comment="kernel-devel is earlier than 0:2.6.18-92.1.18.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:39338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140682" version="1" comment="kernel-xen is earlier than 0:2.6.18-92.1.17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:39082"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140655" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:39082"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140617" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:39082"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140612" version="1" comment="kernel-headers is earlier than 0:2.6.18-92.1.17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:39082"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140603" version="1" comment="kernel-devel is earlier than 0:2.6.18-92.1.17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:39082"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140546" version="1" comment="kernel-doc is earlier than 0:2.6.18-92.1.17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:39082"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140544" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.18.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:39338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140536" version="1" comment="kernel-PAE is earlier than 0:2.6.18-92.1.17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:39082"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140495" version="1" comment="kernel-headers is earlier than 0:2.6.18-92.1.18.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:39338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140491" version="1" comment="kernel-doc is earlier than 0:2.6.18-92.1.18.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:39338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140484" version="1" comment="kernel is earlier than 0:2.6.18-92.1.18.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:39338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140437" version="1" comment="kernel-debug is earlier than 0:2.6.18-92.1.18.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:39338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140260" version="1" comment="kernel-debug is earlier than 0:2.6.18-92.1.17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:39082"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139968" version="1" comment="kernel is earlier than 0:2.6.18-92.1.17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:39082"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139934" version="1" comment="kernel-PAE is earlier than 0:2.6.18-92.1.18.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:39338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140629" version="1" comment="samba-client is earlier than 0:3.0.33-0.18.el4_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13861"/>
      <state state_ref="oval:org.mitre.oval:ste:38898"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140564" version="1" comment="samba-swat is earlier than 0:3.0.33-3.15.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13707"/>
      <state state_ref="oval:org.mitre.oval:ste:38718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140460" version="1" comment="samba-common is earlier than 0:3.0.33-3.15.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14032"/>
      <state state_ref="oval:org.mitre.oval:ste:38718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140319" version="1" comment="samba-swat is earlier than 0:3.0.33-0.18.el4_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13707"/>
      <state state_ref="oval:org.mitre.oval:ste:38898"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140064" version="1" comment="samba-client is earlier than 0:3.0.33-3.15.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13861"/>
      <state state_ref="oval:org.mitre.oval:ste:38718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140058" version="1" comment="samba is earlier than 0:3.0.33-0.18.el4_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13931"/>
      <state state_ref="oval:org.mitre.oval:ste:38898"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139908" version="1" comment="samba is earlier than 0:3.0.33-3.15.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13931"/>
      <state state_ref="oval:org.mitre.oval:ste:38718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139800" version="1" comment="samba-common is earlier than 0:3.0.33-0.18.el4_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14032"/>
      <state state_ref="oval:org.mitre.oval:ste:38898"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140092" version="1" comment="acpid is earlier than 0:1.0.4-9.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14820"/>
      <state state_ref="oval:org.mitre.oval:ste:39138"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140376" version="1" comment="NetworkManager-glib-devel is earlier than 1:0.7.0-4.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15012"/>
      <state state_ref="oval:org.mitre.oval:ste:39189"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140366" version="1" comment="NetworkManager is earlier than 1:0.7.0-4.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15163"/>
      <state state_ref="oval:org.mitre.oval:ste:39189"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140088" version="1" comment="NetworkManager-devel is earlier than 1:0.7.0-4.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14736"/>
      <state state_ref="oval:org.mitre.oval:ste:39189"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140085" version="1" comment="NetworkManager-gnome is earlier than 1:0.7.0-4.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15031"/>
      <state state_ref="oval:org.mitre.oval:ste:39189"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139966" version="1" comment="NetworkManager-glib is earlier than 1:0.7.0-4.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14206"/>
      <state state_ref="oval:org.mitre.oval:ste:39189"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140515" version="1" comment="avahi-devel is earlier than 0:0.6.16-1.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14981"/>
      <state state_ref="oval:org.mitre.oval:ste:39380"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140423" version="1" comment="avahi-tools is earlier than 0:0.6.16-1.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15172"/>
      <state state_ref="oval:org.mitre.oval:ste:39380"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140416" version="1" comment="avahi-compat-libdns_sd-devel is earlier than 0:0.6.16-1.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14977"/>
      <state state_ref="oval:org.mitre.oval:ste:39380"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140409" version="1" comment="avahi-glib-devel is earlier than 0:0.6.16-1.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14417"/>
      <state state_ref="oval:org.mitre.oval:ste:39380"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140407" version="1" comment="avahi-compat-howl-devel is earlier than 0:0.6.16-1.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14459"/>
      <state state_ref="oval:org.mitre.oval:ste:39380"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140389" version="1" comment="avahi-qt3 is earlier than 0:0.6.16-1.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14742"/>
      <state state_ref="oval:org.mitre.oval:ste:39380"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140334" version="1" comment="avahi-compat-howl is earlier than 0:0.6.16-1.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14998"/>
      <state state_ref="oval:org.mitre.oval:ste:39380"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140321" version="1" comment="avahi-compat-libdns_sd is earlier than 0:0.6.16-1.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14856"/>
      <state state_ref="oval:org.mitre.oval:ste:39380"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140297" version="1" comment="avahi-qt3-devel is earlier than 0:0.6.16-1.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14570"/>
      <state state_ref="oval:org.mitre.oval:ste:39380"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140247" version="1" comment="avahi-glib is earlier than 0:0.6.16-1.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14590"/>
      <state state_ref="oval:org.mitre.oval:ste:39380"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140073" version="1" comment="avahi is earlier than 0:0.6.16-1.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14891"/>
      <state state_ref="oval:org.mitre.oval:ste:39380"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140891" version="1" comment="gdm is earlier than 1:2.16.0-56.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14698"/>
      <state state_ref="oval:org.mitre.oval:ste:38523"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140886" version="1" comment="gdm-docs is earlier than 1:2.16.0-56.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15107"/>
      <state state_ref="oval:org.mitre.oval:ste:38523"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140634" version="1" comment="gdm is earlier than 1:2.16.0-56.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14698"/>
      <state state_ref="oval:org.mitre.oval:ste:39471"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140213" version="1" comment="gdm-docs is earlier than 1:2.16.0-56.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15107"/>
      <state state_ref="oval:org.mitre.oval:ste:39471"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141046" version="1" comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_8.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14273"/>
      <state state_ref="oval:org.mitre.oval:ste:38550"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141037" version="1" comment="ruby-irb is earlier than 0:1.8.5-5.el5_3.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14777"/>
      <state state_ref="oval:org.mitre.oval:ste:39502"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140994" version="1" comment="ruby-libs is earlier than 0:1.8.1-7.el4_8.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14388"/>
      <state state_ref="oval:org.mitre.oval:ste:38550"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140989" version="1" comment="ruby-mode is earlier than 0:1.8.5-5.el5_3.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14380"/>
      <state state_ref="oval:org.mitre.oval:ste:39502"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140972" version="1" comment="ruby-devel is earlier than 0:1.8.1-7.el4_8.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14187"/>
      <state state_ref="oval:org.mitre.oval:ste:38550"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140968" version="1" comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_3.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14244"/>
      <state state_ref="oval:org.mitre.oval:ste:39502"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140930" version="1" comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_3.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14273"/>
      <state state_ref="oval:org.mitre.oval:ste:39502"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140913" version="1" comment="irb is earlier than 0:1.8.1-7.el4_8.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13649"/>
      <state state_ref="oval:org.mitre.oval:ste:38550"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140885" version="1" comment="ruby-docs is earlier than 0:1.8.5-5.el5_3.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14446"/>
      <state state_ref="oval:org.mitre.oval:ste:39502"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140833" version="1" comment="ruby-docs is earlier than 0:1.8.1-7.el4_8.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14446"/>
      <state state_ref="oval:org.mitre.oval:ste:38550"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140762" version="1" comment="ruby-devel is earlier than 0:1.8.5-5.el5_3.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14187"/>
      <state state_ref="oval:org.mitre.oval:ste:39502"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140665" version="1" comment="ruby-libs is earlier than 0:1.8.5-5.el5_3.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14388"/>
      <state state_ref="oval:org.mitre.oval:ste:39502"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140542" version="1" comment="ruby is earlier than 0:1.8.1-7.el4_8.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14305"/>
      <state state_ref="oval:org.mitre.oval:ste:38550"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140486" version="1" comment="ruby-mode is earlier than 0:1.8.1-7.el4_8.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14380"/>
      <state state_ref="oval:org.mitre.oval:ste:38550"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140095" version="1" comment="ruby-ri is earlier than 0:1.8.5-5.el5_3.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14461"/>
      <state state_ref="oval:org.mitre.oval:ste:39502"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140046" version="1" comment="ruby is earlier than 0:1.8.5-5.el5_3.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14305"/>
      <state state_ref="oval:org.mitre.oval:ste:39502"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139259" version="1" comment="bluez-libs is earlier than 0:2.10-3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14979"/>
      <state state_ref="oval:org.mitre.oval:ste:38638"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139237" version="1" comment="bluez-libs-devel is earlier than 0:2.10-3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14975"/>
      <state state_ref="oval:org.mitre.oval:ste:38638"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139181" version="1" comment="bluez-utils-cups is earlier than 0:3.7-2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14559"/>
      <state state_ref="oval:org.mitre.oval:ste:38742"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139117" version="1" comment="bluez-libs-devel is earlier than 0:3.7-1.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14975"/>
      <state state_ref="oval:org.mitre.oval:ste:38815"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139067" version="1" comment="bluez-utils is earlier than 0:2.10-2.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14881"/>
      <state state_ref="oval:org.mitre.oval:ste:38819"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139020" version="1" comment="bluez-utils-cups is earlier than 0:2.10-2.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14559"/>
      <state state_ref="oval:org.mitre.oval:ste:38819"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138707" version="1" comment="bluez-utils is earlier than 0:3.7-2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14881"/>
      <state state_ref="oval:org.mitre.oval:ste:38742"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138482" version="1" comment="bluez-libs is earlier than 0:3.7-1.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14979"/>
      <state state_ref="oval:org.mitre.oval:ste:38815"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140831" version="1" comment="cscope is earlier than 0:15.5-15.1.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14970"/>
      <state state_ref="oval:org.mitre.oval:ste:38828"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140473" version="1" comment="netpbm is earlier than 0:10.25-2.1.el4_7.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14185"/>
      <state state_ref="oval:org.mitre.oval:ste:39161"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140336" version="1" comment="netpbm-progs is earlier than 0:10.35-6.1.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13960"/>
      <state state_ref="oval:org.mitre.oval:ste:39387"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140332" version="1" comment="netpbm-devel is earlier than 0:10.35-6.1.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14399"/>
      <state state_ref="oval:org.mitre.oval:ste:39387"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140272" version="1" comment="netpbm-devel is earlier than 0:10.25-2.1.el4_7.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14399"/>
      <state state_ref="oval:org.mitre.oval:ste:39161"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140201" version="1" comment="netpbm-progs is earlier than 0:10.25-2.1.el4_7.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13960"/>
      <state state_ref="oval:org.mitre.oval:ste:39161"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140004" version="1" comment="netpbm is earlier than 0:10.35-6.1.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14185"/>
      <state state_ref="oval:org.mitre.oval:ste:39387"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139307" version="1" comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:38328"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139290" version="1" comment="libxml2 is earlier than 0:2.6.16-12.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:39027"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139288" version="1" comment="libxml2 is earlier than 0:2.6.26-2.1.2.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:38285"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139280" version="1" comment="libxml2-python is earlier than 0:2.6.26-2.1.2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:38328"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139272" version="1" comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:38285"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139255" version="1" comment="libxml2-devel is earlier than 0:2.6.16-12.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:39027"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139230" version="1" comment="libxml2-devel is earlier than 0:2.5.10-11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:38860"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139189" version="1" comment="libxml2 is earlier than 0:2.6.26-2.1.2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:38328"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139002" version="1" comment="libxml2-python is earlier than 0:2.6.16-12.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:39027"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138985" version="1" comment="libxml2-python is earlier than 0:2.5.10-11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:38860"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138962" version="1" comment="libxml2 is earlier than 0:2.5.10-11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:38860"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138587" version="1" comment="libxml2-python is earlier than 0:2.6.26-2.1.2.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:38285"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140786" version="1" comment="devhelp-devel is earlier than 0:0.12-20.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14520"/>
      <state state_ref="oval:org.mitre.oval:ste:39397"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140718" version="1" comment="yelp is earlier than 0:2.16.0-22.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14764"/>
      <state state_ref="oval:org.mitre.oval:ste:39122"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140705" version="1" comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:39019"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140686" version="1" comment="nss is earlier than 0:3.12.1.1-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:38929"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140658" version="1" comment="devhelp is earlier than 0:0.12-20.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14497"/>
      <state state_ref="oval:org.mitre.oval:ste:39397"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140636" version="1" comment="firefox is earlier than 0:3.0.4-1.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:38468"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140626" version="1" comment="nss-devel is earlier than 0:3.12.1.1-3.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:38978"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140618" version="1" comment="nss-tools is earlier than 0:3.12.1.1-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:38929"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140539" version="1" comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:38929"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140533" version="1" comment="nss-devel is earlier than 0:3.12.1.1-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:38929"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140481" version="1" comment="nss is earlier than 0:3.12.1.1-3.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:38978"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140479" version="1" comment="nss-devel is earlier than 0:3.12.1.1-3.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:38972"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140428" version="1" comment="nss is earlier than 0:3.12.1.1-3.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:38972"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140415" version="1" comment="firefox is earlier than 0:3.0.4-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:38624"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140400" version="1" comment="nss-tools is earlier than 0:3.12.1.1-3.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:38972"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140399" version="1" comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:38972"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140378" version="1" comment="xulrunner is earlier than 0:1.9.0.4-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:39019"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140180" version="1" comment="firefox is earlier than 0:3.0.4-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39093"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140173" version="1" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15048"/>
      <state state_ref="oval:org.mitre.oval:ste:39019"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140468" version="1" comment="lcms-devel is earlier than 0:1.18-0.1.beta1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14904"/>
      <state state_ref="oval:org.mitre.oval:ste:39187"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140047" version="1" comment="python-lcms is earlier than 0:1.18-0.1.beta1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14958"/>
      <state state_ref="oval:org.mitre.oval:ste:39187"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139897" version="1" comment="lcms is earlier than 0:1.18-0.1.beta1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15079"/>
      <state state_ref="oval:org.mitre.oval:ste:39187"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139007" version="1" comment="rdesktop is earlier than 0:1.4.1-6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14647"/>
      <state state_ref="oval:org.mitre.oval:ste:38230"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140675" version="1" comment="vim-enhanced is earlier than 2:7.0.109-4.el5_2.4z" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14043"/>
      <state state_ref="oval:org.mitre.oval:ste:38804"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140661" version="1" comment="vim-X11 is earlier than 2:7.0.109-4.el5_2.4z" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14549"/>
      <state state_ref="oval:org.mitre.oval:ste:38804"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140608" version="1" comment="vim-minimal is earlier than 2:7.0.109-4.el5_2.4z" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14513"/>
      <state state_ref="oval:org.mitre.oval:ste:38804"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140342" version="1" comment="vim-common is earlier than 2:7.0.109-4.el5_2.4z" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14345"/>
      <state state_ref="oval:org.mitre.oval:ste:38804"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140801" version="1" comment="xulrunner is earlier than 0:1.9.0.15-3.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:39064"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140672" version="1" comment="firefox is earlier than 0:3.0.15-3.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39267"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140615" version="1" comment="nspr is earlier than 0:4.7.6-1.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14745"/>
      <state state_ref="oval:org.mitre.oval:ste:38915"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140529" version="1" comment="xulrunner-devel is earlier than 0:1.9.0.15-3.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:39064"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140404" version="1" comment="nspr is earlier than 0:4.7.6-1.el4_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14745"/>
      <state state_ref="oval:org.mitre.oval:ste:39121"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140382" version="1" comment="nspr-devel is earlier than 0:4.7.6-1.el4_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15145"/>
      <state state_ref="oval:org.mitre.oval:ste:39121"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140313" version="1" comment="firefox is earlier than 0:3.0.15-3.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39111"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140125" version="1" comment="nspr-devel is earlier than 0:4.7.6-1.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15145"/>
      <state state_ref="oval:org.mitre.oval:ste:38915"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139804" version="1" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.15-3.el5_4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15048"/>
      <state state_ref="oval:org.mitre.oval:ste:39064"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139679" version="1" comment="finch-devel is earlier than 0:2.5.9-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:39084"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139666" version="1" comment="libpurple-devel is earlier than 0:2.5.9-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:39084"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139627" version="1" comment="libpurple is earlier than 0:2.5.9-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:39084"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139603" version="1" comment="pidgin is earlier than 0:2.5.9-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:39084"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139582" version="1" comment="libpurple-perl is earlier than 0:2.5.9-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:39047"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139578" version="1" comment="libpurple-tcl is earlier than 0:2.5.9-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:39084"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139572" version="1" comment="pidgin-devel is earlier than 0:2.5.9-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:39084"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139493" version="1" comment="pidgin-perl is earlier than 0:2.5.9-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:39084"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139452" version="1" comment="libpurple-devel is earlier than 0:2.5.9-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:39047"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139437" version="1" comment="pidgin is earlier than 0:1.5.1-4.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:38700"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139377" version="1" comment="pidgin-devel is earlier than 0:2.5.9-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:39047"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139348" version="1" comment="pidgin is earlier than 0:2.5.9-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:39047"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139287" version="1" comment="finch is earlier than 0:2.5.9-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:39084"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139286" version="1" comment="libpurple-tcl is earlier than 0:2.5.9-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:39047"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139041" version="1" comment="finch-devel is earlier than 0:2.5.9-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:39047"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139031" version="1" comment="finch is earlier than 0:2.5.9-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:39047"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138841" version="1" comment="pidgin-perl is earlier than 0:2.5.9-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:39047"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138699" version="1" comment="libpurple-perl is earlier than 0:2.5.9-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:39084"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138688" version="1" comment="libpurple is earlier than 0:2.5.9-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:39047"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140898" version="1" comment="libvorbis-devel is earlier than 1:1.1.0-3.el4_8.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14840"/>
      <state state_ref="oval:org.mitre.oval:ste:38983"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140822" version="1" comment="libvorbis-devel is earlier than 1:1.1.2-3.el5_3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14840"/>
      <state state_ref="oval:org.mitre.oval:ste:39042"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140798" version="1" comment="libvorbis is earlier than 1:1.0-11.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14657"/>
      <state state_ref="oval:org.mitre.oval:ste:39520"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140685" version="1" comment="libvorbis is earlier than 1:1.1.2-3.el5_3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14657"/>
      <state state_ref="oval:org.mitre.oval:ste:39042"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140454" version="1" comment="libvorbis-devel is earlier than 1:1.0-11.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14840"/>
      <state state_ref="oval:org.mitre.oval:ste:39520"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140145" version="1" comment="libvorbis is earlier than 1:1.1.0-3.el4_8.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14657"/>
      <state state_ref="oval:org.mitre.oval:ste:38983"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140657" version="1" comment="nss-devel is earlier than 0:3.12.2.0-2.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:39327"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140624" version="1" comment="nss-devel is earlier than 0:3.12.2.0-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:39367"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140600" version="1" comment="nss is earlier than 0:3.12.2.0-2.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:39327"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140577" version="1" comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-2.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:39327"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140574" version="1" comment="xulrunner is earlier than 0:1.9.0.5-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:39342"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140572" version="1" comment="nspr-devel is earlier than 0:4.7.3-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15145"/>
      <state state_ref="oval:org.mitre.oval:ste:38847"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140570" version="1" comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:39403"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140563" version="1" comment="xulrunner-devel is earlier than 0:1.9.0.5-1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:39162"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140558" version="1" comment="nss is earlier than 0:3.12.2.0-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:39403"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140517" version="1" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.5-1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15048"/>
      <state state_ref="oval:org.mitre.oval:ste:39162"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140512" version="1" comment="xulrunner is earlier than 0:1.9.0.5-1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:39162"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140511" version="1" comment="firefox is earlier than 0:3.0.5-1.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39348"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140480" version="1" comment="nspr is earlier than 0:4.7.3-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14745"/>
      <state state_ref="oval:org.mitre.oval:ste:38847"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140463" version="1" comment="nss-devel is earlier than 0:3.12.2.0-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:39403"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140435" version="1" comment="nspr is earlier than 0:4.7.3-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14745"/>
      <state state_ref="oval:org.mitre.oval:ste:38997"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140417" version="1" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.5-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15048"/>
      <state state_ref="oval:org.mitre.oval:ste:39342"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140363" version="1" comment="firefox is earlier than 0:3.0.5-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39381"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140355" version="1" comment="nss-tools is earlier than 0:3.12.2.0-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:39403"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140348" version="1" comment="nss is earlier than 0:3.12.2.0-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:39367"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140211" version="1" comment="nspr-devel is earlier than 0:4.7.3-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15145"/>
      <state state_ref="oval:org.mitre.oval:ste:38997"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140170" version="1" comment="xulrunner-devel is earlier than 0:1.9.0.5-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:39342"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140133" version="1" comment="nss-tools is earlier than 0:3.12.2.0-2.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:39327"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139656" version="1" comment="firefox is earlier than 0:3.0.5-1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:38963"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140438" version="1" comment="squirrelmail is earlier than 0:1.4.8-5.el5.centos.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14331"/>
      <state state_ref="oval:org.mitre.oval:ste:39044"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140414" version="1" comment="squirrelmail is earlier than 0:1.4.8-9.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14331"/>
      <state state_ref="oval:org.mitre.oval:ste:39182"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140128" version="1" comment="squirrelmail is earlier than 0:1.4.8-5.el5_2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14331"/>
      <state state_ref="oval:org.mitre.oval:ste:39239"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139950" version="1" comment="squirrelmail is earlier than 0:1.4.8-5.el4_7.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14331"/>
      <state state_ref="oval:org.mitre.oval:ste:39130"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139701" version="1" comment="libpurple-tcl is earlier than 0:2.5.2-6.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:38745"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139678" version="1" comment="libpurple-devel is earlier than 0:2.5.2-6.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:38745"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139662" version="1" comment="libpurple-tcl is earlier than 0:2.5.2-6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:38777"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139653" version="1" comment="libpurple is earlier than 0:2.5.2-6.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:38745"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139621" version="1" comment="pidgin-docs is earlier than 0:2.5.2-6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14724"/>
      <state state_ref="oval:org.mitre.oval:ste:38777"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139597" version="1" comment="pidgin is earlier than 0:2.5.2-6.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:38745"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139574" version="1" comment="pidgin-devel is earlier than 0:2.5.2-6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:38777"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139562" version="1" comment="finch-devel is earlier than 0:2.5.2-6.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:38745"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139542" version="1" comment="pidgin-perl is earlier than 0:2.5.2-6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:38777"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139518" version="1" comment="finch-devel is earlier than 0:2.5.2-6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:38777"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139513" version="1" comment="pidgin-perl is earlier than 0:2.5.2-6.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:38745"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139502" version="1" comment="finch is earlier than 0:2.5.2-6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:38777"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139466" version="1" comment="libpurple-devel is earlier than 0:2.5.2-6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:38777"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139429" version="1" comment="pidgin-devel is earlier than 0:2.5.2-6.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:38745"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139426" version="1" comment="libpurple-perl is earlier than 0:2.5.2-6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:38777"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139408" version="1" comment="libpurple is earlier than 0:2.5.2-6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:38777"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139392" version="1" comment="enscript is earlier than 0:1.6.4-4.1.1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14574"/>
      <state state_ref="oval:org.mitre.oval:ste:38592"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139314" version="1" comment="pidgin is earlier than 0:2.5.2-6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:38777"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138716" version="1" comment="libpurple-perl is earlier than 0:2.5.2-6.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:38745"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138690" version="1" comment="finch is earlier than 0:2.5.2-6.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:38745"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141005" version="1" comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14688"/>
      <state state_ref="oval:org.mitre.oval:ste:39548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140962" version="1" comment="cups-libs is earlier than 1:1.3.7-8.el5_3.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14195"/>
      <state state_ref="oval:org.mitre.oval:ste:39548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140915" version="1" comment="cups is earlier than 1:1.3.7-8.el5_3.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14199"/>
      <state state_ref="oval:org.mitre.oval:ste:39548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140422" version="1" comment="cups-devel is earlier than 1:1.3.7-8.el5_3.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14076"/>
      <state state_ref="oval:org.mitre.oval:ste:39548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140983" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.2.b09.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:39456"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140794" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.2.b09.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:39456"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140679" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.2.b09.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:39456"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140519" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.2.b09.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:39456"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140015" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.2.b09.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:39456"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139593" version="1" comment="thunderbird is earlier than 0:2.0.0.19-1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:38833"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139301" version="1" comment="thunderbird is earlier than 0:1.5.0.12-18.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:38567"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139101" version="1" comment="thunderbird is earlier than 0:2.0.0.19-1.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:38848"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139066" version="1" comment="ed is earlier than 0:0.2-33.30E.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15110"/>
      <state state_ref="oval:org.mitre.oval:ste:38938"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139005" version="1" comment="ed is earlier than 0:0.2-36.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15110"/>
      <state state_ref="oval:org.mitre.oval:ste:38595"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139003" version="1" comment="ed is earlier than 0:0.2-39.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15110"/>
      <state state_ref="oval:org.mitre.oval:ste:39124"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140780" version="1" comment="net-snmp-utils is earlier than 1:5.0.9-2.30E.25" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14287"/>
      <state state_ref="oval:org.mitre.oval:ste:39215"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140771" version="1" comment="net-snmp is earlier than 1:5.3.1-24.el5_2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14390"/>
      <state state_ref="oval:org.mitre.oval:ste:39373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140768" version="1" comment="net-snmp-libs is earlier than 1:5.1.2-13.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14316"/>
      <state state_ref="oval:org.mitre.oval:ste:38643"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140764" version="1" comment="net-snmp-perl is earlier than 1:5.1.2-13.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14516"/>
      <state state_ref="oval:org.mitre.oval:ste:38643"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140746" version="1" comment="net-snmp-perl is earlier than 1:5.0.9-2.30E.25" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14516"/>
      <state state_ref="oval:org.mitre.oval:ste:39215"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140733" version="1" comment="net-snmp is earlier than 1:5.1.2-13.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14390"/>
      <state state_ref="oval:org.mitre.oval:ste:38643"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140649" version="1" comment="net-snmp-devel is earlier than 1:5.3.1-24.el5_2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14339"/>
      <state state_ref="oval:org.mitre.oval:ste:39373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140641" version="1" comment="net-snmp-utils is earlier than 1:5.3.1-24.el5_2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14287"/>
      <state state_ref="oval:org.mitre.oval:ste:39373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140637" version="1" comment="net-snmp is earlier than 1:5.0.9-2.30E.25" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14390"/>
      <state state_ref="oval:org.mitre.oval:ste:39215"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140589" version="1" comment="net-snmp-libs is earlier than 1:5.3.1-24.el5_2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14316"/>
      <state state_ref="oval:org.mitre.oval:ste:39373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140557" version="1" comment="net-snmp-utils is earlier than 1:5.1.2-13.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14287"/>
      <state state_ref="oval:org.mitre.oval:ste:38643"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140354" version="1" comment="net-snmp-devel is earlier than 1:5.1.2-13.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14339"/>
      <state state_ref="oval:org.mitre.oval:ste:38643"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140294" version="1" comment="net-snmp-libs is earlier than 1:5.0.9-2.30E.25" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14316"/>
      <state state_ref="oval:org.mitre.oval:ste:39215"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140286" version="1" comment="net-snmp-devel is earlier than 1:5.0.9-2.30E.25" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14339"/>
      <state state_ref="oval:org.mitre.oval:ste:39215"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140054" version="1" comment="net-snmp-perl is earlier than 1:5.3.1-24.el5_2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14516"/>
      <state state_ref="oval:org.mitre.oval:ste:39373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140434" version="1" comment="libpng10-devel is earlier than 2:1.0.16-3.el4_7.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:347"/>
      <state state_ref="oval:org.mitre.oval:ste:39232"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140306" version="1" comment="libpng10 is earlier than 2:1.0.16-3.el4_7.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:346"/>
      <state state_ref="oval:org.mitre.oval:ste:39232"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140264" version="1" comment="libpng-devel is earlier than 2:1.2.7-3.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:951"/>
      <state state_ref="oval:org.mitre.oval:ste:39279"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140228" version="1" comment="libpng is earlier than 2:1.2.7-3.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:952"/>
      <state state_ref="oval:org.mitre.oval:ste:39279"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140055" version="1" comment="libpng-devel is earlier than 2:1.2.10-7.1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:951"/>
      <state state_ref="oval:org.mitre.oval:ste:39335"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140045" version="1" comment="libpng is earlier than 2:1.2.10-7.1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:952"/>
      <state state_ref="oval:org.mitre.oval:ste:39335"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140448" version="1" comment="icu is earlier than 0:3.6-5.11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14949"/>
      <state state_ref="oval:org.mitre.oval:ste:39100"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140374" version="1" comment="libicu-doc is earlier than 0:3.6-5.11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14890"/>
      <state state_ref="oval:org.mitre.oval:ste:39100"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140335" version="1" comment="libicu is earlier than 0:3.6-5.11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14735"/>
      <state state_ref="oval:org.mitre.oval:ste:39100"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140237" version="1" comment="libicu-devel is earlier than 0:3.6-5.11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14587"/>
      <state state_ref="oval:org.mitre.oval:ste:39100"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139459" version="1" comment="kdegraphics-devel is earlier than 7:3.5.4-12.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14596"/>
      <state state_ref="oval:org.mitre.oval:ste:39207"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139444" version="1" comment="kdegraphics is earlier than 7:3.3.1-13.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14241"/>
      <state state_ref="oval:org.mitre.oval:ste:38934"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139227" version="1" comment="kdegraphics-devel is earlier than 7:3.3.1-13.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14596"/>
      <state state_ref="oval:org.mitre.oval:ste:38934"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139206" version="1" comment="kdegraphics is earlier than 7:3.5.4-12.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14241"/>
      <state state_ref="oval:org.mitre.oval:ste:39207"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139246" version="1" comment="openssh-clients is earlier than 0:4.3p2-26.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14409"/>
      <state state_ref="oval:org.mitre.oval:ste:38879"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139241" version="1" comment="openssh-askpass-gnome is earlier than 0:3.9p1-11.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14434"/>
      <state state_ref="oval:org.mitre.oval:ste:39105"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139218" version="1" comment="openssh-server is earlier than 0:3.9p1-11.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14544"/>
      <state state_ref="oval:org.mitre.oval:ste:39105"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139215" version="1" comment="openssh-askpass is earlier than 0:4.3p2-26.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14577"/>
      <state state_ref="oval:org.mitre.oval:ste:38879"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139199" version="1" comment="openssh is earlier than 0:4.3p2-26.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14581"/>
      <state state_ref="oval:org.mitre.oval:ste:38879"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139057" version="1" comment="openssh is earlier than 0:3.9p1-11.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14581"/>
      <state state_ref="oval:org.mitre.oval:ste:39105"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138970" version="1" comment="openssh-server is earlier than 0:4.3p2-26.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14544"/>
      <state state_ref="oval:org.mitre.oval:ste:38879"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138943" version="1" comment="openssh-askpass is earlier than 0:3.9p1-11.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14577"/>
      <state state_ref="oval:org.mitre.oval:ste:39105"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138914" version="1" comment="openssh-clients is earlier than 0:3.9p1-11.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14409"/>
      <state state_ref="oval:org.mitre.oval:ste:39105"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140697" version="1" comment="squirrelmail is earlier than 0:1.4.8-5.el5_4.10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14331"/>
      <state state_ref="oval:org.mitre.oval:ste:39297"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140565" version="1" comment="squirrelmail is earlier than 0:1.4.8-5.el4_8.8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14331"/>
      <state state_ref="oval:org.mitre.oval:ste:39340"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140248" version="1" comment="squirrelmail is earlier than 0:1.4.8-16.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14331"/>
      <state state_ref="oval:org.mitre.oval:ste:38880"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140978" version="1" comment="firefox is earlier than 0:3.0.12-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39411"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140971" version="1" comment="xulrunner-devel is earlier than 0:1.9.0.12-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:39040"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140947" version="1" comment="xulrunner-devel is earlier than 0:1.9.0.12-1.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:39336"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140903" version="1" comment="firefox is earlier than 0:3.0.12-1.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39530"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140836" version="1" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.12-1.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15048"/>
      <state state_ref="oval:org.mitre.oval:ste:39336"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140628" version="1" comment="xulrunner is earlier than 0:1.9.0.12-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:39040"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140477" version="1" comment="xulrunner is earlier than 0:1.9.0.12-1.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:39336"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140439" version="1" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.12-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15048"/>
      <state state_ref="oval:org.mitre.oval:ste:39040"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140017" version="1" comment="firefox is earlier than 0:3.0.12-1.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39043"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139114" version="1" comment="cups-lpd is earlier than 1:1.2.4-11.18.el5_2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14688"/>
      <state state_ref="oval:org.mitre.oval:ste:39076"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139113" version="1" comment="cups-devel is earlier than 1:1.2.4-11.18.el5_2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14076"/>
      <state state_ref="oval:org.mitre.oval:ste:39076"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139059" version="1" comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14199"/>
      <state state_ref="oval:org.mitre.oval:ste:38251"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139023" version="1" comment="cups-devel is earlier than 1:1.1.17-13.3.54" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14076"/>
      <state state_ref="oval:org.mitre.oval:ste:38319"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138986" version="1" comment="cups-libs is earlier than 1:1.1.17-13.3.54" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14195"/>
      <state state_ref="oval:org.mitre.oval:ste:38319"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138971" version="1" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14076"/>
      <state state_ref="oval:org.mitre.oval:ste:38251"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138755" version="1" comment="cups is earlier than 1:1.1.17-13.3.54" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14199"/>
      <state state_ref="oval:org.mitre.oval:ste:38319"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138730" version="1" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14195"/>
      <state state_ref="oval:org.mitre.oval:ste:38251"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138560" version="1" comment="cups-libs is earlier than 1:1.2.4-11.18.el5_2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14195"/>
      <state state_ref="oval:org.mitre.oval:ste:39076"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138134" version="1" comment="cups is earlier than 1:1.2.4-11.18.el5_2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14199"/>
      <state state_ref="oval:org.mitre.oval:ste:39076"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139169" version="1" comment="thunderbird is earlier than 0:2.0.0.22-2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:38846"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139051" version="1" comment="thunderbird is earlier than 0:2.0.0.22-2.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:38787"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140931" version="1" comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.7.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14808"/>
      <state state_ref="oval:org.mitre.oval:ste:39441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140916" version="1" comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.7.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14210"/>
      <state state_ref="oval:org.mitre.oval:ste:39441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140908" version="1" comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.7.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14332"/>
      <state state_ref="oval:org.mitre.oval:ste:39441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140875" version="1" comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.7.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14509"/>
      <state state_ref="oval:org.mitre.oval:ste:39441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140872" version="1" comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.7.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14750"/>
      <state state_ref="oval:org.mitre.oval:ste:39441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140852" version="1" comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.7.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14686"/>
      <state state_ref="oval:org.mitre.oval:ste:39441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140659" version="1" comment="tomcat5 is earlier than 0:5.5.23-0jpp.7.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14612"/>
      <state state_ref="oval:org.mitre.oval:ste:39441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140578" version="1" comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.7.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14685"/>
      <state state_ref="oval:org.mitre.oval:ste:39441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140568" version="1" comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.7.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14815"/>
      <state state_ref="oval:org.mitre.oval:ste:39441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140467" version="1" comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.7.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14622"/>
      <state state_ref="oval:org.mitre.oval:ste:39441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140447" version="1" comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.7.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14662"/>
      <state state_ref="oval:org.mitre.oval:ste:39441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140429" version="1" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15048"/>
      <state state_ref="oval:org.mitre.oval:ste:38928"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140377" version="1" comment="xulrunner-devel is earlier than 0:1.9.0.7-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:38928"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140375" version="1" comment="xulrunner is earlier than 0:1.9.0.7-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:38928"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140261" version="1" comment="firefox is earlier than 0:3.0.7-3.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:38998"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140458" version="1" comment="ghostscript is earlier than 0:8.15.2-9.4.el5_3.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14541"/>
      <state state_ref="oval:org.mitre.oval:ste:39308"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140393" version="1" comment="ghostscript is earlier than 0:7.05-32.1.17" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14541"/>
      <state state_ref="oval:org.mitre.oval:ste:39110"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140381" version="1" comment="ghostscript-devel is earlier than 0:7.07-33.2.el4_7.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14524"/>
      <state state_ref="oval:org.mitre.oval:ste:39361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140320" version="1" comment="ghostscript-devel is earlier than 0:8.15.2-9.4.el5_3.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14524"/>
      <state state_ref="oval:org.mitre.oval:ste:39308"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140285" version="1" comment="ghostscript-gtk is earlier than 0:7.07-33.2.el4_7.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14614"/>
      <state state_ref="oval:org.mitre.oval:ste:39361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140281" version="1" comment="hpijs is earlier than 0:1.3-32.1.17" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14471"/>
      <state state_ref="oval:org.mitre.oval:ste:38716"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140107" version="1" comment="ghostscript-devel is earlier than 0:7.05-32.1.17" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14524"/>
      <state state_ref="oval:org.mitre.oval:ste:39110"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139961" version="1" comment="ghostscript is earlier than 0:7.07-33.2.el4_7.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14541"/>
      <state state_ref="oval:org.mitre.oval:ste:39361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139652" version="1" comment="ghostscript-gtk is earlier than 0:8.15.2-9.4.el5_3.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14614"/>
      <state state_ref="oval:org.mitre.oval:ste:39308"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140266" version="1" comment="libvorbis is earlier than 1:1.0-12.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14657"/>
      <state state_ref="oval:org.mitre.oval:ste:38956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140206" version="1" comment="libvorbis-devel is earlier than 1:1.0-12.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14840"/>
      <state state_ref="oval:org.mitre.oval:ste:38956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140124" version="1" comment="libvorbis is earlier than 1:1.1.0-3.el4_8.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14657"/>
      <state state_ref="oval:org.mitre.oval:ste:39302"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140011" version="1" comment="libvorbis-devel is earlier than 1:1.1.0-3.el4_8.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14840"/>
      <state state_ref="oval:org.mitre.oval:ste:39302"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139939" version="1" comment="libvorbis-devel is earlier than 1:1.1.2-3.el5_4.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14840"/>
      <state state_ref="oval:org.mitre.oval:ste:39303"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139936" version="1" comment="libvorbis is earlier than 1:1.1.2-3.el5_4.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14657"/>
      <state state_ref="oval:org.mitre.oval:ste:39303"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140990" version="1" comment="nss-devel is earlier than 0:3.12.3.99.3-1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:39325"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140868" version="1" comment="nspr is earlier than 0:4.7.4-1.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14745"/>
      <state state_ref="oval:org.mitre.oval:ste:39326"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140787" version="1" comment="nss-tools is earlier than 0:3.12.3.99.3-1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:39325"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140727" version="1" comment="nss-pkcs11-devel is earlier than 0:3.12.3.99.3-1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:39325"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140616" version="1" comment="nspr-devel is earlier than 0:4.7.4-1.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15145"/>
      <state state_ref="oval:org.mitre.oval:ste:39326"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140172" version="1" comment="nss is earlier than 0:3.12.3.99.3-1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:39325"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139204" version="1" comment="dnsmasq is earlier than 0:2.45-1.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14690"/>
      <state state_ref="oval:org.mitre.oval:ste:38825"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139524" version="1" comment="thunderbird is earlier than 0:2.0.0.21-1.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:38345"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139441" version="1" comment="thunderbird is earlier than 0:1.5.0.12-19.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:39163"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138696" version="1" comment="thunderbird is earlier than 0:2.0.0.21-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:38589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140958" version="1" comment="subversion-perl is earlier than 0:1.4.2-4.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14470"/>
      <state state_ref="oval:org.mitre.oval:ste:39497"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140899" version="1" comment="mod_dav_svn is earlier than 0:1.1.4-3.el4_8.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14514"/>
      <state state_ref="oval:org.mitre.oval:ste:39077"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140893" version="1" comment="mod_dav_svn is earlier than 0:1.4.2-4.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14514"/>
      <state state_ref="oval:org.mitre.oval:ste:39497"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140890" version="1" comment="subversion-javahl is earlier than 0:1.4.2-4.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15180"/>
      <state state_ref="oval:org.mitre.oval:ste:39497"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140826" version="1" comment="subversion-ruby is earlier than 0:1.4.2-4.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15192"/>
      <state state_ref="oval:org.mitre.oval:ste:39497"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140738" version="1" comment="subversion-devel is earlier than 0:1.4.2-4.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14983"/>
      <state state_ref="oval:org.mitre.oval:ste:39497"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140532" version="1" comment="subversion-devel is earlier than 0:1.1.4-3.el4_8.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14983"/>
      <state state_ref="oval:org.mitre.oval:ste:39077"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140509" version="1" comment="subversion-perl is earlier than 0:1.1.4-3.el4_8.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14470"/>
      <state state_ref="oval:org.mitre.oval:ste:39077"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140452" version="1" comment="subversion is earlier than 0:1.1.4-3.el4_8.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15298"/>
      <state state_ref="oval:org.mitre.oval:ste:39077"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139972" version="1" comment="subversion is earlier than 0:1.4.2-4.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15298"/>
      <state state_ref="oval:org.mitre.oval:ste:39497"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139990" version="1" comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14432"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139989" version="1" comment="openoffice.org-langpack-ml_IN is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14257"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139978" version="1" comment="openoffice.org-langpack-ga_IE is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14635"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139975" version="1" comment="openoffice.org-langpack-sl_SI is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14869"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139970" version="1" comment="openoffice.org-langpack-hi_IN is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14717"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139947" version="1" comment="openoffice.org-langpack-pl_PL is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14767"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139945" version="1" comment="openoffice.org-langpack-th_TH is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14732"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139940" version="1" comment="openoffice.org-langpack-zh_CN is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14839"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139928" version="1" comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14056"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139926" version="1" comment="openoffice.org-langpack-ru is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14766"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139920" version="1" comment="openoffice.org-langpack-ja_JP is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14155"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139910" version="1" comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14728"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139904" version="1" comment="openoffice.org-langpack-hr_HR is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14336"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139903" version="1" comment="openoffice.org-calc is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14623"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139899" version="1" comment="openoffice.org-xsltfilter is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14530"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139898" version="1" comment="openoffice.org-sdk is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14664"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139895" version="1" comment="openoffice.org-langpack-bn is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14706"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139891" version="1" comment="openoffice.org-langpack-tr_TR is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14886"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139890" version="1" comment="openoffice.org-langpack-ms_MY is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14787"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139888" version="1" comment="openoffice.org-langpack-mr_IN is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14855"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139880" version="1" comment="openoffice.org-math is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14557"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139879" version="1" comment="openoffice.org-langpack-sk_SK is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14266"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139873" version="1" comment="openoffice.org-langpack-nl is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14909"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139868" version="1" comment="openoffice.org-langpack-as_IN is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14576"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139861" version="1" comment="openoffice.org-langpack-pt_BR is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14822"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139844" version="1" comment="openoffice.org-graphicfilter is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14526"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139830" version="1" comment="openoffice.org-langpack-ur is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14671"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139828" version="1" comment="openoffice.org-langpack-fi_FI is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14625"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139824" version="1" comment="openoffice.org-langpack-kn_IN is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14714"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139815" version="1" comment="openoffice.org-sdk-doc is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14165"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139812" version="1" comment="openoffice.org-draw is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14828"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139806" version="1" comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14738"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139796" version="1" comment="openoffice.org-impress is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14707"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139770" version="1" comment="openoffice.org-langpack-gu_IN is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14269"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139765" version="1" comment="openoffice.org-langpack-ar is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14872"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139743" version="1" comment="openoffice.org-langpack-af_ZA is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14506"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139742" version="1" comment="openoffice.org-langpack-bg_BG is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14589"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139739" version="1" comment="openoffice.org-langpack-es is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14604"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139738" version="1" comment="openoffice.org-langpack-fr is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14772"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139716" version="1" comment="openoffice.org-langpack-ta_IN is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14637"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139714" version="1" comment="openoffice.org-testtools is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14135"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139710" version="1" comment="openoffice.org-langpack-or_IN is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14588"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139704" version="1" comment="openoffice.org-javafilter is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14566"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139700" version="1" comment="openoffice.org-langpack-eu_ES is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14813"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139693" version="1" comment="openoffice.org-pyuno is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14806"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139692" version="1" comment="openoffice.org-langpack-et_EE is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14280"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139674" version="1" comment="openoffice.org-core is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14450"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139647" version="1" comment="openoffice.org-base is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14548"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139636" version="1" comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14651"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139629" version="1" comment="openoffice.org-langpack-he_IL is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14442"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139623" version="1" comment="openoffice.org-langpack-sv is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14529"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139613" version="1" comment="openoffice.org-headless is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14864"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139579" version="1" comment="openoffice.org-langpack-te_IN is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14832"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139565" version="1" comment="openoffice.org-emailmerge is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14522"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139558" version="1" comment="openoffice.org-langpack-zh_TW is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14392"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139551" version="1" comment="openoffice.org-langpack-it is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14812"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139549" version="1" comment="openoffice.org-langpack-sr_CS is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14189"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139543" version="1" comment="openoffice.org-langpack-nn_NO is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14779"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139541" version="1" comment="openoffice.org-langpack-nb_NO is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14807"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139512" version="1" comment="openoffice.org-langpack-hu_HU is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14694"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139511" version="1" comment="openoffice.org-langpack-gl_ES is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14792"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139482" version="1" comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14562"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139462" version="1" comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14900"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139394" version="1" comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14865"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139375" version="1" comment="openoffice.org-langpack-st_ZA is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14851"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139362" version="1" comment="openoffice.org-langpack-cy_GB is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14501"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139347" version="1" comment="openoffice.org-langpack-ca_ES is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14778"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139345" version="1" comment="openoffice.org-langpack-lt_LT is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13921"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139343" version="1" comment="openoffice.org-langpack-pa_IN is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14746"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139331" version="1" comment="openoffice.org-langpack-ko_KR is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14190"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139302" version="1" comment="openoffice.org-langpack-pt_PT is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14571"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139165" version="1" comment="openoffice.org-langpack-de is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14539"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139144" version="1" comment="openoffice.org-langpack-da_DK is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14748"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139081" version="1" comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13974"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139037" version="1" comment="openoffice.org-writer is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14758"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138994" version="1" comment="openoffice.org-langpack-el_GR is earlier than 1:2.3.0-6.5.2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14359"/>
      <state state_ref="oval:org.mitre.oval:ste:38569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141008" version="1" comment="kernel-xen is earlier than 0:2.6.18-128.4.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:39426"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140981" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-128.4.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:39426"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140973" version="1" comment="kernel is earlier than 0:2.6.18-128.4.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:39426"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140939" version="1" comment="kernel-headers is earlier than 0:2.6.18-128.4.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:39426"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140937" version="1" comment="kernel-doc is earlier than 0:2.6.18-128.4.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:39426"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140912" version="1" comment="kernel-PAE is earlier than 0:2.6.18-128.4.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:39426"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140858" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-128.4.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:39426"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140666" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.4.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:39426"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140579" version="1" comment="kernel-devel is earlier than 0:2.6.18-128.4.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:39426"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140432" version="1" comment="kernel-debug is earlier than 0:2.6.18-128.4.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:39426"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140871" version="1" comment="kernel-doc is earlier than 0:2.6.18-164.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:38955"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140791" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-164.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:38955"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140730" version="1" comment="kernel-PAE is earlier than 0:2.6.18-164.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:38955"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140620" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-164.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:38955"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140619" version="1" comment="kernel-debug is earlier than 0:2.6.18-164.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:38955"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140581" version="1" comment="kernel-headers is earlier than 0:2.6.18-164.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:38955"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140552" version="1" comment="kernel-xen is earlier than 0:2.6.18-164.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:38955"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140502" version="1" comment="kernel-devel is earlier than 0:2.6.18-164.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:38955"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140315" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-164.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:38955"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140284" version="1" comment="kernel is earlier than 0:2.6.18-164.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:38955"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139329" version="1" comment="php-devel is earlier than 0:5.1.6-20.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13492"/>
      <state state_ref="oval:org.mitre.oval:ste:39109"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139276" version="1" comment="php-gd is earlier than 0:5.1.6-20.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14335"/>
      <state state_ref="oval:org.mitre.oval:ste:39109"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139275" version="1" comment="php-ncurses is earlier than 0:5.1.6-20.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14227"/>
      <state state_ref="oval:org.mitre.oval:ste:39109"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139266" version="1" comment="php-mysql is earlier than 0:5.1.6-20.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14080"/>
      <state state_ref="oval:org.mitre.oval:ste:39109"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139257" version="1" comment="php-ldap is earlier than 0:4.3.2-48.ent" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14375"/>
      <state state_ref="oval:org.mitre.oval:ste:38871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139231" version="1" comment="php-soap is earlier than 0:5.1.6-20.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14366"/>
      <state state_ref="oval:org.mitre.oval:ste:39109"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139194" version="1" comment="php-ldap is earlier than 0:5.1.6-20.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14375"/>
      <state state_ref="oval:org.mitre.oval:ste:39109"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139193" version="1" comment="php-devel is earlier than 0:4.3.2-48.ent" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13492"/>
      <state state_ref="oval:org.mitre.oval:ste:38871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139184" version="1" comment="php-imap is earlier than 0:4.3.2-48.ent" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14250"/>
      <state state_ref="oval:org.mitre.oval:ste:38871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139179" version="1" comment="php-pgsql is earlier than 0:4.3.2-48.ent" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14148"/>
      <state state_ref="oval:org.mitre.oval:ste:38871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139159" version="1" comment="php-odbc is earlier than 0:4.3.2-48.ent" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14183"/>
      <state state_ref="oval:org.mitre.oval:ste:38871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139149" version="1" comment="php-common is earlier than 0:5.1.6-20.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14841"/>
      <state state_ref="oval:org.mitre.oval:ste:39109"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139139" version="1" comment="php-mbstring is earlier than 0:5.1.6-20.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13746"/>
      <state state_ref="oval:org.mitre.oval:ste:39109"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139128" version="1" comment="php-odbc is earlier than 0:5.1.6-20.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14183"/>
      <state state_ref="oval:org.mitre.oval:ste:39109"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139124" version="1" comment="php-dba is earlier than 0:5.1.6-20.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14512"/>
      <state state_ref="oval:org.mitre.oval:ste:39109"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139056" version="1" comment="php is earlier than 0:5.1.6-20.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14294"/>
      <state state_ref="oval:org.mitre.oval:ste:39109"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139044" version="1" comment="php-bcmath is earlier than 0:5.1.6-20.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14639"/>
      <state state_ref="oval:org.mitre.oval:ste:39109"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139024" version="1" comment="php-pdo is earlier than 0:5.1.6-20.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14154"/>
      <state state_ref="oval:org.mitre.oval:ste:39109"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139019" version="1" comment="php-pgsql is earlier than 0:5.1.6-20.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14148"/>
      <state state_ref="oval:org.mitre.oval:ste:39109"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138915" version="1" comment="php-xml is earlier than 0:5.1.6-20.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14560"/>
      <state state_ref="oval:org.mitre.oval:ste:39109"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138818" version="1" comment="php is earlier than 0:4.3.2-48.ent" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14294"/>
      <state state_ref="oval:org.mitre.oval:ste:38871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138786" version="1" comment="php-xmlrpc is earlier than 0:5.1.6-20.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14445"/>
      <state state_ref="oval:org.mitre.oval:ste:39109"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138671" version="1" comment="php-cli is earlier than 0:5.1.6-20.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14922"/>
      <state state_ref="oval:org.mitre.oval:ste:39109"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138603" version="1" comment="php-mysql is earlier than 0:4.3.2-48.ent" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14080"/>
      <state state_ref="oval:org.mitre.oval:ste:38871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138598" version="1" comment="php-imap is earlier than 0:5.1.6-20.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14250"/>
      <state state_ref="oval:org.mitre.oval:ste:39109"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138416" version="1" comment="php-snmp is earlier than 0:5.1.6-20.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14508"/>
      <state state_ref="oval:org.mitre.oval:ste:39109"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140033" version="1" comment="pidgin is earlier than 0:1.5.1-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:38877"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140003" version="1" comment="libpurple-devel is earlier than 0:2.3.1-2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:38891"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139977" version="1" comment="pidgin is earlier than 0:2.3.1-2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:38891"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139951" version="1" comment="libpurple-tcl is earlier than 0:2.3.1-2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:38891"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139919" version="1" comment="pidgin is earlier than 0:1.5.1-2.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:39151"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139869" version="1" comment="pidgin-perl is earlier than 0:2.3.1-2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:38891"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139856" version="1" comment="finch-devel is earlier than 0:2.3.1-2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:38891"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139849" version="1" comment="libpurple-perl is earlier than 0:2.3.1-2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:38891"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139818" version="1" comment="finch is earlier than 0:2.3.1-2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:38891"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139797" version="1" comment="pidgin-devel is earlier than 0:2.3.1-2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:38891"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139728" version="1" comment="libpurple is earlier than 0:2.3.1-2.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:38891"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140550" version="1" comment="xterm is earlier than 0:179-11.EL3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14838"/>
      <state state_ref="oval:org.mitre.oval:ste:39034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140441" version="1" comment="xterm is earlier than 0:215-5.el5_2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14838"/>
      <state state_ref="oval:org.mitre.oval:ste:39286"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140418" version="1" comment="xterm is earlier than 0:192-8.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14838"/>
      <state state_ref="oval:org.mitre.oval:ste:39393"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140224" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.35-1.13.7.1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:38912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140221" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.35-1.13.7.1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:38912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140204" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.35-1.13.7.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:38315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140190" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.35-1.13.7.1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:39197"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140123" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.35-1.13.7.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:38315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140122" version="1" comment="java-1.6.0-openjdk-debuginfo is earlier than 1:1.6.0.35-1.13.7.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42919"/>
      <state state_ref="oval:org.mitre.oval:ste:38315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140101" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.35-1.13.7.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:38315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140057" version="1" comment="java-1.6.0-openjdk-debuginfo is earlier than 1:1.6.0.35-1.13.7.1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42919"/>
      <state state_ref="oval:org.mitre.oval:ste:38912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140018" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.35-1.13.7.1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:38912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139981" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.35-1.13.7.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:38315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139980" version="1" comment="java-1.6.0-openjdk-debuginfo is earlier than 1:1.6.0.35-1.13.7.1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42919"/>
      <state state_ref="oval:org.mitre.oval:ste:39197"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139857" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.35-1.13.7.1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:38912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139711" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.35-1.13.7.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:38315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139697" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.35-1.13.7.1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:38912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139601" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.35-1.13.7.1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:39197"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139599" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.35-1.13.7.1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:39197"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139581" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.35-1.13.7.1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:39197"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139368" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.35-1.13.7.1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:39197"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140673" version="1" comment="cups-lpd is earlier than 1:1.2.4-11.18.el5_2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14688"/>
      <state state_ref="oval:org.mitre.oval:ste:38953"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140521" version="1" comment="cups-libs is earlier than 1:1.2.4-11.18.el5_2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14195"/>
      <state state_ref="oval:org.mitre.oval:ste:38953"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140311" version="1" comment="cups is earlier than 1:1.2.4-11.18.el5_2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14199"/>
      <state state_ref="oval:org.mitre.oval:ste:38953"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140300" version="1" comment="cups-devel is earlier than 1:1.2.4-11.18.el5_2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14076"/>
      <state state_ref="oval:org.mitre.oval:ste:38953"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140863" version="1" comment="curl is earlier than 0:7.12.1-11.1.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14575"/>
      <state state_ref="oval:org.mitre.oval:ste:39389"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140855" version="1" comment="curl-devel is earlier than 0:7.10.6-10.rhel3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14469"/>
      <state state_ref="oval:org.mitre.oval:ste:39314"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140825" version="1" comment="curl-devel is earlier than 0:7.15.5-2.1.el5_3.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14469"/>
      <state state_ref="oval:org.mitre.oval:ste:39398"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140810" version="1" comment="curl is earlier than 0:7.15.5-2.1.el5_3.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14575"/>
      <state state_ref="oval:org.mitre.oval:ste:39398"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140551" version="1" comment="curl-devel is earlier than 0:7.12.1-11.1.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14469"/>
      <state state_ref="oval:org.mitre.oval:ste:39389"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140420" version="1" comment="curl is earlier than 0:7.10.6-10.rhel3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14575"/>
      <state state_ref="oval:org.mitre.oval:ste:39314"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139326" version="1" comment="postfix is earlier than 0:2.3.3-2.1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1466"/>
      <state state_ref="oval:org.mitre.oval:ste:39057"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139324" version="1" comment="libsane-hpaio is earlier than 0:1.6.7-4.1.el5_2.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14491"/>
      <state state_ref="oval:org.mitre.oval:ste:38757"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139170" version="1" comment="hplip is earlier than 0:1.6.7-4.1.el5_2.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3847"/>
      <state state_ref="oval:org.mitre.oval:ste:38757"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139153" version="1" comment="hpijs is earlier than 0:1.6.7-4.1.el5_2.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14471"/>
      <state state_ref="oval:org.mitre.oval:ste:38757"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138478" version="1" comment="postfix-pflogsumm is earlier than 0:2.3.3-2.1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14593"/>
      <state state_ref="oval:org.mitre.oval:ste:39057"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139270" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.13.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:38986"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139263" version="1" comment="kernel-PAE is earlier than 0:2.6.18-92.1.13.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:38986"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139248" version="1" comment="kernel-headers is earlier than 0:2.6.18-92.1.13.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:38986"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139093" version="1" comment="kernel-xen is earlier than 0:2.6.18-92.1.13.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:38986"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139088" version="1" comment="kernel-devel is earlier than 0:2.6.18-92.1.13.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:38986"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139084" version="1" comment="kernel is earlier than 0:2.6.18-92.1.13.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:38986"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139083" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.13.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:38986"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139028" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.13.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:38986"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138876" version="1" comment="kernel-doc is earlier than 0:2.6.18-92.1.13.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:38986"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138408" version="1" comment="kernel-debug is earlier than 0:2.6.18-92.1.13.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:38986"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139665" version="1" comment="kdegraphics-devel is earlier than 7:3.5.4-13.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14596"/>
      <state state_ref="oval:org.mitre.oval:ste:39224"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139130" version="1" comment="kdegraphics is earlier than 7:3.5.4-13.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14241"/>
      <state state_ref="oval:org.mitre.oval:ste:39224"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139120" version="1" comment="thunderbird is earlier than 0:2.0.0.18-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:39054"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139082" version="1" comment="thunderbird is earlier than 0:2.0.0.18-1.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:38916"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139039" version="1" comment="thunderbird is earlier than 0:1.5.0.12-17.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:39101"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139654" version="1" comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14754"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139649" version="1" comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14882"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139648" version="1" comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14814"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139646" version="1" comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14369"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139643" version="1" comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14763"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139641" version="1" comment="openoffice.org-libs is earlier than 1:1.1.2-44.2.0.EL3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14455"/>
      <state state_ref="oval:org.mitre.oval:ste:39051"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139640" version="1" comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14456"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139635" version="1" comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14995"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139633" version="1" comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14907"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139625" version="1" comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14969"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139619" version="1" comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14716"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139617" version="1" comment="openoffice.org-langpack-pt_BR is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14822"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139610" version="1" comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14990"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139608" version="1" comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14193"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139607" version="1" comment="openoffice.org-langpack-pl_PL is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14767"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139606" version="1" comment="openoffice.org-math is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14557"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139604" version="1" comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14562"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139598" version="1" comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15018"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139596" version="1" comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15005"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139580" version="1" comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14696"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139577" version="1" comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14708"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139576" version="1" comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14987"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139573" version="1" comment="openoffice.org-langpack-ml_IN is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14257"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139571" version="1" comment="openoffice.org-libs is earlier than 1:1.1.5-10.6.0.7.EL4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14455"/>
      <state state_ref="oval:org.mitre.oval:ste:39159"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139569" version="1" comment="openoffice.org-langpack-ru is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14766"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139568" version="1" comment="openoffice.org-langpack-sr_CS is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14189"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139567" version="1" comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14849"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139559" version="1" comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14892"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139557" version="1" comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14649"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139554" version="1" comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14744"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139553" version="1" comment="openoffice.org-i18n is earlier than 1:1.1.2-44.2.0.EL3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14215"/>
      <state state_ref="oval:org.mitre.oval:ste:39051"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139546" version="1" comment="openoffice.org-langpack-sk_SK is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14266"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139544" version="1" comment="openoffice.org-langpack-zh_TW is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14392"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139539" version="1" comment="openoffice.org-i18n is earlier than 1:1.1.5-10.6.0.7.EL4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14215"/>
      <state state_ref="oval:org.mitre.oval:ste:39159"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139530" version="1" comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14997"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139525" version="1" comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14875"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139523" version="1" comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14056"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139519" version="1" comment="openoffice.org-langpack-ms_MY is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14787"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139517" version="1" comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14963"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139516" version="1" comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14831"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139514" version="1" comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14401"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139508" version="1" comment="openoffice.org is earlier than 1:1.1.2-44.2.0.EL3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13461"/>
      <state state_ref="oval:org.mitre.oval:ste:39051"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139506" version="1" comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14660"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139503" version="1" comment="openoffice.org-langpack-tr_TR is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14886"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139483" version="1" comment="openoffice.org-javafilter is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14566"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139474" version="1" comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14569"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139473" version="1" comment="openoffice.org-langpack-he_IL is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14442"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139458" version="1" comment="openoffice.org-langpack-pt_PT is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14571"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139456" version="1" comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14600"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139455" version="1" comment="openoffice.org-langpack-hu_HU is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14694"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139450" version="1" comment="openoffice.org-langpack-te_IN is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14832"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139449" version="1" comment="openoffice.org-langpack-el_GR is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14359"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139436" version="1" comment="openoffice.org-langpack-pa_IN is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14746"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139435" version="1" comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14090"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139434" version="1" comment="openoffice.org-langpack-de is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14539"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139432" version="1" comment="openoffice.org-langpack-hr_HR is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14336"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139431" version="1" comment="openoffice.org-langpack-ga_IE is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14635"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139423" version="1" comment="openoffice.org-langpack-eu_ES is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14813"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139422" version="1" comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14971"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139419" version="1" comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14599"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139417" version="1" comment="openoffice.org-impress is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14707"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139411" version="1" comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14900"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139405" version="1" comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14617"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139403" version="1" comment="openoffice.org-langpack-sl_SI is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14869"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139401" version="1" comment="openoffice.org-graphicfilter is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14526"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139388" version="1" comment="openoffice.org-pyuno is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14806"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139383" version="1" comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14937"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139380" version="1" comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14737"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139379" version="1" comment="openoffice.org-langpack-sv is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14529"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139376" version="1" comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14976"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139371" version="1" comment="openoffice.org-langpack-et_EE is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14280"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139369" version="1" comment="openoffice.org-langpack-mr_IN is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14855"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139366" version="1" comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14834"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139364" version="1" comment="openoffice.org-langpack-bg_BG is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14589"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139363" version="1" comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14759"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139354" version="1" comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14845"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139353" version="1" comment="openoffice.org-langpack-es is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14604"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139350" version="1" comment="openoffice.org-langpack-zh_CN is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14839"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139344" version="1" comment="openoffice.org-langpack-th_TH is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14732"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139342" version="1" comment="openoffice.org-langpack-nl is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14909"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139339" version="1" comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14980"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139338" version="1" comment="openoffice.org-langpack-or_IN is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14588"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139337" version="1" comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14901"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139332" version="1" comment="openoffice.org-langpack-gu_IN is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14269"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139325" version="1" comment="openoffice.org-langpack-ko_KR is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14190"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139323" version="1" comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14986"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139322" version="1" comment="openoffice.org-calc is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14623"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139321" version="1" comment="openoffice.org-langpack-ta_IN is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14637"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139320" version="1" comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14321"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139319" version="1" comment="openoffice.org-emailmerge is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14522"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139316" version="1" comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14765"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139315" version="1" comment="openoffice.org-langpack-da_DK is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14748"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139312" version="1" comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14476"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139295" version="1" comment="openoffice.org-headless is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14864"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139285" version="1" comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14738"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139279" version="1" comment="openoffice.org-langpack-ur is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14671"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139274" version="1" comment="openoffice.org-langpack-it is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14812"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139258" version="1" comment="openoffice.org-langpack-gl_ES is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14792"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139243" version="1" comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14432"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139233" version="1" comment="openoffice.org-core is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14450"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139232" version="1" comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14651"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139220" version="1" comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14984"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139212" version="1" comment="openoffice.org-langpack-fr is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14772"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139203" version="1" comment="openoffice.org-langpack-nb_NO is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14807"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139202" version="1" comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14865"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139201" version="1" comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14322"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139187" version="1" comment="openoffice.org-langpack-cy_GB is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14501"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139185" version="1" comment="openoffice.org-langpack-lt_LT is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13921"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139180" version="1" comment="openoffice.org-langpack-nn_NO is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14779"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139172" version="1" comment="openoffice.org-langpack-as_IN is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14576"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139162" version="1" comment="openoffice.org-kde is earlier than 1:1.1.5-10.6.0.7.EL4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13698"/>
      <state state_ref="oval:org.mitre.oval:ste:39159"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139161" version="1" comment="openoffice.org-sdk-doc is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14165"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139154" version="1" comment="openoffice.org-writer is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14758"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139147" version="1" comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15000"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139142" version="1" comment="openoffice.org-langpack-hi_IN is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14717"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139141" version="1" comment="openoffice.org-draw is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14828"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139132" version="1" comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14728"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139126" version="1" comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14762"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139123" version="1" comment="openoffice.org-langpack-af_ZA is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14506"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139118" version="1" comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13974"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139112" version="1" comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14472"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139107" version="1" comment="openoffice.org-langpack-ca_ES is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14778"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139105" version="1" comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14885"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139074" version="1" comment="openoffice.org-langpack-kn_IN is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14714"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139022" version="1" comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15006"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138976" version="1" comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14606"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138975" version="1" comment="openoffice.org is earlier than 1:1.1.5-10.6.0.7.EL4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13461"/>
      <state state_ref="oval:org.mitre.oval:ste:39159"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138969" version="1" comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14894"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138967" version="1" comment="openoffice.org-langpack-st_ZA is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14851"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138960" version="1" comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14903"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138928" version="1" comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14956"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138912" version="1" comment="openoffice.org-sdk is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14664"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138887" version="1" comment="openoffice.org-testtools is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14135"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138837" version="1" comment="openoffice.org-langpack-fi_FI is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14625"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138806" version="1" comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14826"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138782" version="1" comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.6.0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14768"/>
      <state state_ref="oval:org.mitre.oval:ste:39140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138759" version="1" comment="openoffice.org-langpack-ar is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14872"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138681" version="1" comment="openoffice.org-base is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14548"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138675" version="1" comment="openoffice.org-langpack-bn is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14706"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138655" version="1" comment="openoffice.org-xsltfilter is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14530"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138625" version="1" comment="openoffice.org-langpack-ja_JP is earlier than 1:2.3.0-6.11.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14155"/>
      <state state_ref="oval:org.mitre.oval:ste:38856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139681" version="1" comment="pidgin-perl is earlier than 0:2.5.5-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:38903"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139634" version="1" comment="pidgin is earlier than 0:2.5.5-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:38903"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139628" version="1" comment="libpurple-perl is earlier than 0:2.5.5-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:38969"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139616" version="1" comment="libpurple-perl is earlier than 0:2.5.5-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:38903"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139605" version="1" comment="pidgin is earlier than 0:2.5.5-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:38969"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139587" version="1" comment="finch-devel is earlier than 0:2.5.5-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:38969"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139586" version="1" comment="libpurple-tcl is earlier than 0:2.5.5-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:38969"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139538" version="1" comment="pidgin-devel is earlier than 0:2.5.5-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:38969"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139489" version="1" comment="libpurple is earlier than 0:2.5.5-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:38969"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139481" version="1" comment="libpurple is earlier than 0:2.5.5-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:38903"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139476" version="1" comment="libpurple-tcl is earlier than 0:2.5.5-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:38903"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139400" version="1" comment="pidgin-perl is earlier than 0:2.5.5-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:38969"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139391" version="1" comment="finch-devel is earlier than 0:2.5.5-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:38903"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139367" version="1" comment="libpurple-devel is earlier than 0:2.5.5-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:38903"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139335" version="1" comment="finch is earlier than 0:2.5.5-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:38903"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139278" version="1" comment="finch is earlier than 0:2.5.5-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:38969"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139196" version="1" comment="libpurple-devel is earlier than 0:2.5.5-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:38969"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139158" version="1" comment="pidgin-devel is earlier than 0:2.5.5-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:38903"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140263" version="1" comment="bind-sdb is earlier than 30:9.3.6-4.P1.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:39250"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140262" version="1" comment="bind-libbind-devel is earlier than 30:9.3.6-4.P1.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14729"/>
      <state state_ref="oval:org.mitre.oval:ste:39250"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140118" version="1" comment="bind-libs is earlier than 30:9.3.6-4.P1.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:39250"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140025" version="1" comment="bind-utils is earlier than 30:9.3.6-4.P1.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:39250"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139884" version="1" comment="bind-devel is earlier than 30:9.3.6-4.P1.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:39250"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139792" version="1" comment="caching-nameserver is earlier than 30:9.3.6-4.P1.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14701"/>
      <state state_ref="oval:org.mitre.oval:ste:39250"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139733" version="1" comment="bind-chroot is earlier than 30:9.3.6-4.P1.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:39250"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139719" version="1" comment="bind is earlier than 30:9.3.6-4.P1.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:39250"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141051" version="1" comment="openswan-doc is earlier than 0:2.6.14-1.el5_3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15278"/>
      <state state_ref="oval:org.mitre.oval:ste:39483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141031" version="1" comment="openswan is earlier than 0:2.6.14-1.el5_3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14994"/>
      <state state_ref="oval:org.mitre.oval:ste:39483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139676" version="1" comment="pidgin is earlier than 0:2.5.8-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:38767"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139630" version="1" comment="libpurple-tcl is earlier than 0:2.5.8-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:38767"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139614" version="1" comment="pidgin-devel is earlier than 0:2.5.8-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:38767"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139612" version="1" comment="finch is earlier than 0:2.5.8-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:38655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139585" version="1" comment="finch-devel is earlier than 0:2.5.8-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:38767"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139575" version="1" comment="libpurple-devel is earlier than 0:2.5.8-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:38767"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139566" version="1" comment="libpurple-perl is earlier than 0:2.5.8-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:38767"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139522" version="1" comment="finch is earlier than 0:2.5.8-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:38767"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139510" version="1" comment="pidgin-perl is earlier than 0:2.5.8-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:38767"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139457" version="1" comment="libpurple is earlier than 0:2.5.8-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:38767"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139407" version="1" comment="libpurple-perl is earlier than 0:2.5.8-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:38655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139365" version="1" comment="finch-devel is earlier than 0:2.5.8-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:38655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139217" version="1" comment="libpurple-devel is earlier than 0:2.5.8-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:38655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139182" version="1" comment="libpurple is earlier than 0:2.5.8-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:38655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139155" version="1" comment="libpurple-tcl is earlier than 0:2.5.8-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:38655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139122" version="1" comment="pidgin-devel is earlier than 0:2.5.8-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:38655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138984" version="1" comment="pidgin-perl is earlier than 0:2.5.8-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:38655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138936" version="1" comment="pidgin is earlier than 0:2.5.8-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:38655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140379" version="1" comment="sudo is earlier than 0:1.6.9p17-3.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14246"/>
      <state state_ref="oval:org.mitre.oval:ste:38862"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141074" version="1" comment="freetype is earlier than 0:2.2.1-21.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14103"/>
      <state state_ref="oval:org.mitre.oval:ste:39527"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141027" version="1" comment="freetype-devel is earlier than 0:2.2.1-21.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14561"/>
      <state state_ref="oval:org.mitre.oval:ste:39527"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140797" version="1" comment="freetype-demos is earlier than 0:2.2.1-21.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14713"/>
      <state state_ref="oval:org.mitre.oval:ste:39527"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139085" version="1" comment="pam_krb5 is earlier than 0:2.2.14-1.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15087"/>
      <state state_ref="oval:org.mitre.oval:ste:38924"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140440" version="1" comment="wireshark-gnome is earlier than 0:1.0.6-2.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14663"/>
      <state state_ref="oval:org.mitre.oval:ste:39223"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140361" version="1" comment="wireshark is earlier than 0:1.0.6-EL3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14711"/>
      <state state_ref="oval:org.mitre.oval:ste:39262"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140273" version="1" comment="wireshark-gnome is earlier than 0:1.0.6-EL3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14663"/>
      <state state_ref="oval:org.mitre.oval:ste:39262"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140245" version="1" comment="wireshark is earlier than 0:1.0.6-2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14711"/>
      <state state_ref="oval:org.mitre.oval:ste:38933"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140214" version="1" comment="wireshark-gnome is earlier than 0:1.0.6-2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14663"/>
      <state state_ref="oval:org.mitre.oval:ste:38933"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140181" version="1" comment="wireshark is earlier than 0:1.0.6-2.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14711"/>
      <state state_ref="oval:org.mitre.oval:ste:39223"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140235" version="1" comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.79-2.5.5.2.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29032"/>
      <state state_ref="oval:org.mitre.oval:ste:39080"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140197" version="1" comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.79-2.5.5.2.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29256"/>
      <state state_ref="oval:org.mitre.oval:ste:39080"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140036" version="1" comment="java-1.7.0-openjdk is earlier than 1:1.7.0.79-2.5.5.2.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28860"/>
      <state state_ref="oval:org.mitre.oval:ste:39080"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139773" version="1" comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.79-2.5.5.2.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28946"/>
      <state state_ref="oval:org.mitre.oval:ste:39080"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139564" version="1" comment="java-1.7.0-openjdk-debuginfo is earlier than 1:1.7.0.79-2.5.5.2.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:44089"/>
      <state state_ref="oval:org.mitre.oval:ste:39080"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139563" version="1" comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.79-2.5.5.2.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29000"/>
      <state state_ref="oval:org.mitre.oval:ste:39080"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141018" version="1" comment="perl-DBD-Pg is earlier than 0:1.49-2.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15165"/>
      <state state_ref="oval:org.mitre.oval:ste:39235"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140951" version="1" comment="apr-util-devel is earlier than 0:0.9.4-22.el4_8.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15236"/>
      <state state_ref="oval:org.mitre.oval:ste:39447"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140848" version="1" comment="apr-util-devel is earlier than 0:1.2.7-7.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15236"/>
      <state state_ref="oval:org.mitre.oval:ste:39407"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140814" version="1" comment="apr-devel is earlier than 0:0.9.4-24.9.el4_8.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15174"/>
      <state state_ref="oval:org.mitre.oval:ste:39332"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140804" version="1" comment="apr-util is earlier than 0:0.9.4-22.el4_8.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14992"/>
      <state state_ref="oval:org.mitre.oval:ste:39447"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140737" version="1" comment="apr-util is earlier than 0:1.2.7-7.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14992"/>
      <state state_ref="oval:org.mitre.oval:ste:39407"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140708" version="1" comment="apr-util-docs is earlier than 0:1.2.7-7.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15199"/>
      <state state_ref="oval:org.mitre.oval:ste:39407"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140648" version="1" comment="apr is earlier than 0:1.2.7-11.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15116"/>
      <state state_ref="oval:org.mitre.oval:ste:39374"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140538" version="1" comment="apr is earlier than 0:0.9.4-24.9.el4_8.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15116"/>
      <state state_ref="oval:org.mitre.oval:ste:39332"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140494" version="1" comment="apr-docs is earlier than 0:1.2.7-11.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15034"/>
      <state state_ref="oval:org.mitre.oval:ste:39374"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139952" version="1" comment="apr-devel is earlier than 0:1.2.7-11.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15174"/>
      <state state_ref="oval:org.mitre.oval:ste:39374"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139907" version="1" comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14875"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139859" version="1" comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14997"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139858" version="1" comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14660"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139846" version="1" comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14762"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139836" version="1" comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14956"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139831" version="1" comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14476"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139827" version="1" comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14995"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139825" version="1" comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14903"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139821" version="1" comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14849"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139817" version="1" comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14971"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139813" version="1" comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14617"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139807" version="1" comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15000"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139802" version="1" comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14737"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139790" version="1" comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14322"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139782" version="1" comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14562"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139780" version="1" comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14976"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139779" version="1" comment="openoffice.org-langpack-pt_PT is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14571"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139775" version="1" comment="openoffice.org-langpack-pa_IN is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14746"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139774" version="1" comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15018"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139771" version="1" comment="openoffice.org-langpack-pl_PL is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14767"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139769" version="1" comment="openoffice.org-langpack-pt_BR is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14822"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139768" version="1" comment="openoffice.org-langpack-th_TH is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14732"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139766" version="1" comment="openoffice.org-langpack-ms_MY is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14787"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139762" version="1" comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15005"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139759" version="1" comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14969"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139756" version="1" comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14900"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139755" version="1" comment="openoffice.org-langpack-mr_IN is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14855"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139754" version="1" comment="openoffice.org-libs is earlier than 1:1.1.2-43.2.0.EL3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14455"/>
      <state state_ref="oval:org.mitre.oval:ste:38358"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139753" version="1" comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15006"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139752" version="1" comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14826"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139750" version="1" comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14980"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139749" version="1" comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14432"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139748" version="1" comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14763"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139747" version="1" comment="openoffice.org-langpack-or_IN is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14588"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139737" version="1" comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14831"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139731" version="1" comment="openoffice.org is earlier than 1:1.1.5-10.6.0.7.EL4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13461"/>
      <state state_ref="oval:org.mitre.oval:ste:39217"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139724" version="1" comment="openoffice.org is earlier than 1:1.1.2-43.2.0.EL3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13461"/>
      <state state_ref="oval:org.mitre.oval:ste:38358"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139722" version="1" comment="openoffice.org-langpack-gl_ES is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14792"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139721" version="1" comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14738"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139715" version="1" comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14708"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139712" version="1" comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14456"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139709" version="1" comment="openoffice.org-langpack-lt_LT is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13921"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139708" version="1" comment="openoffice.org-langpack-ko_KR is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14190"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139706" version="1" comment="openoffice.org-langpack-ru is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14766"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139705" version="1" comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14986"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139703" version="1" comment="openoffice.org-langpack-nl is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14909"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139702" version="1" comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14765"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139698" version="1" comment="openoffice.org-testtools is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14135"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139696" version="1" comment="openoffice.org-langpack-ml_IN is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14257"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139695" version="1" comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14401"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139691" version="1" comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14599"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139688" version="1" comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14569"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139687" version="1" comment="openoffice.org-graphicfilter is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14526"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139686" version="1" comment="openoffice.org-langpack-sv is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14529"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139685" version="1" comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13974"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139684" version="1" comment="openoffice.org-langpack-es is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14604"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139683" version="1" comment="openoffice.org-langpack-ja_JP is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14155"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139682" version="1" comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14716"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139680" version="1" comment="openoffice.org-langpack-el_GR is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14359"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139673" version="1" comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14963"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139671" version="1" comment="openoffice.org-langpack-te_IN is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14832"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139668" version="1" comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14882"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139664" version="1" comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14834"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139661" version="1" comment="openoffice.org-langpack-nn_NO is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14779"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139659" version="1" comment="openoffice.org-langpack-da_DK is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14748"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139658" version="1" comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14885"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139655" version="1" comment="openoffice.org-langpack-eu_ES is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14813"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139650" version="1" comment="openoffice.org-langpack-fr is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14772"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139644" version="1" comment="openoffice.org-headless is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14864"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139638" version="1" comment="openoffice.org-langpack-zh_CN is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14839"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139637" version="1" comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14768"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139631" version="1" comment="openoffice.org-javafilter is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14566"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139626" version="1" comment="openoffice.org-langpack-et_EE is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14280"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139622" version="1" comment="openoffice.org-langpack-de is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14539"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139618" version="1" comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14369"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139600" version="1" comment="openoffice.org-draw is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14828"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139595" version="1" comment="openoffice.org-langpack-nb_NO is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14807"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139589" version="1" comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14193"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139570" version="1" comment="openoffice.org-langpack-st_ZA is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14851"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139560" version="1" comment="openoffice.org-langpack-sk_SK is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14266"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139556" version="1" comment="openoffice.org-langpack-bg_BG is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14589"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139547" version="1" comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14937"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139545" version="1" comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14892"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139537" version="1" comment="openoffice.org-langpack-fi_FI is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14625"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139534" version="1" comment="openoffice.org-i18n is earlier than 1:1.1.5-10.6.0.7.EL4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14215"/>
      <state state_ref="oval:org.mitre.oval:ste:39217"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139532" version="1" comment="openoffice.org-langpack-ca_ES is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14778"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139531" version="1" comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14649"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139528" version="1" comment="openoffice.org-math is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14557"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139527" version="1" comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14907"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139521" version="1" comment="openoffice.org-langpack-ur is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14671"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139507" version="1" comment="openoffice.org-langpack-kn_IN is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14714"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139499" version="1" comment="openoffice.org-sdk is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14664"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139498" version="1" comment="openoffice.org-langpack-ta_IN is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14637"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139495" version="1" comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14744"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139492" version="1" comment="openoffice.org-kde is earlier than 1:1.1.5-10.6.0.7.EL4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13698"/>
      <state state_ref="oval:org.mitre.oval:ste:39217"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139491" version="1" comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14321"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139486" version="1" comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14814"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139478" version="1" comment="openoffice.org-libs is earlier than 1:1.1.5-10.6.0.7.EL4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14455"/>
      <state state_ref="oval:org.mitre.oval:ste:39217"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139464" version="1" comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14651"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139454" version="1" comment="openoffice.org-langpack-ga_IE is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14635"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139445" version="1" comment="openoffice.org-base is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14548"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139438" version="1" comment="openoffice.org-sdk-doc is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14165"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139428" version="1" comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14056"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139412" version="1" comment="openoffice.org-langpack-zh_TW is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14392"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139410" version="1" comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14987"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139397" version="1" comment="openoffice.org-langpack-it is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14812"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139389" version="1" comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14845"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139372" version="1" comment="openoffice.org-langpack-ar is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14872"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139370" version="1" comment="openoffice.org-calc is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14623"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139359" version="1" comment="openoffice.org-writer is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14758"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139349" version="1" comment="openoffice.org-langpack-gu_IN is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14269"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139336" version="1" comment="openoffice.org-langpack-hu_HU is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14694"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139334" version="1" comment="openoffice.org-langpack-af_ZA is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14506"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139318" version="1" comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14759"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139297" version="1" comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14606"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139296" version="1" comment="openoffice.org-langpack-as_IN is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14576"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139283" version="1" comment="openoffice.org-langpack-hi_IN is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14717"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139282" version="1" comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14901"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139267" version="1" comment="openoffice.org-impress is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14707"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139226" version="1" comment="openoffice.org-emailmerge is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14522"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139211" version="1" comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14754"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139191" version="1" comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14990"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139190" version="1" comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14472"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139188" version="1" comment="openoffice.org-langpack-tr_TR is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14886"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139164" version="1" comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14865"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139163" version="1" comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14696"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139156" version="1" comment="openoffice.org-langpack-hr_HR is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14336"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139119" version="1" comment="openoffice.org-pyuno is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14806"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139106" version="1" comment="openoffice.org-langpack-sl_SI is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14869"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139063" version="1" comment="openoffice.org-core is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14450"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139027" version="1" comment="openoffice.org-langpack-cy_GB is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14501"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139025" version="1" comment="openoffice.org-xsltfilter is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14530"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139015" version="1" comment="openoffice.org-langpack-sr_CS is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14189"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138978" version="1" comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14600"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138956" version="1" comment="openoffice.org-i18n is earlier than 1:1.1.2-43.2.0.EL3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14215"/>
      <state state_ref="oval:org.mitre.oval:ste:38358"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138950" version="1" comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14728"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138925" version="1" comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14984"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138858" version="1" comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14090"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138857" version="1" comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.6.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14894"/>
      <state state_ref="oval:org.mitre.oval:ste:39193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138784" version="1" comment="openoffice.org-langpack-he_IL is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14442"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138726" version="1" comment="openoffice.org-langpack-bn is earlier than 1:2.3.0-6.5.4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14706"/>
      <state state_ref="oval:org.mitre.oval:ste:38842"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140370" version="1" comment="glib2 is earlier than 0:2.12.3-4.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:5095"/>
      <state state_ref="oval:org.mitre.oval:ste:38971"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140252" version="1" comment="glib2-devel is earlier than 0:2.12.3-4.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:5050"/>
      <state state_ref="oval:org.mitre.oval:ste:38971"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139327" version="1" comment="devhelp is earlier than 0:0.12-18.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14497"/>
      <state state_ref="oval:org.mitre.oval:ste:39113"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139309" version="1" comment="firefox is earlier than 0:3.0.1-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:38647"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139303" version="1" comment="xulrunner is earlier than 0:1.9.0.1-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:39171"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139157" version="1" comment="xulrunner-devel is earlier than 0:1.9.0.1-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:39171"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139151" version="1" comment="yelp is earlier than 0:2.16.0-20.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14764"/>
      <state state_ref="oval:org.mitre.oval:ste:39024"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139129" version="1" comment="nspluginwrapper is earlier than 0:0.9.91.5-22.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14675"/>
      <state state_ref="oval:org.mitre.oval:ste:39183"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139065" version="1" comment="devhelp-devel is earlier than 0:0.12-18.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14520"/>
      <state state_ref="oval:org.mitre.oval:ste:39113"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138992" version="1" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.1-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15048"/>
      <state state_ref="oval:org.mitre.oval:ste:39171"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140755" version="1" comment="cman-devel is earlier than 0:2.0.115-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14802"/>
      <state state_ref="oval:org.mitre.oval:ste:38831"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140609" version="1" comment="cman is earlier than 0:2.0.115-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14620"/>
      <state state_ref="oval:org.mitre.oval:ste:38831"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140271" version="1" comment="xerces-j2-demo is earlier than 0:2.7.1-7jpp.2.el5_4.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15310"/>
      <state state_ref="oval:org.mitre.oval:ste:38395"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140265" version="1" comment="xerces-j2-javadoc-apis is earlier than 0:2.7.1-7jpp.2.el5_4.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14948"/>
      <state state_ref="oval:org.mitre.oval:ste:38395"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140176" version="1" comment="xerces-j2-javadoc-impl is earlier than 0:2.7.1-7jpp.2.el5_4.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14818"/>
      <state state_ref="oval:org.mitre.oval:ste:38395"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139894" version="1" comment="xerces-j2-javadoc-xni is earlier than 0:2.7.1-7jpp.2.el5_4.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15179"/>
      <state state_ref="oval:org.mitre.oval:ste:38395"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139866" version="1" comment="xerces-j2-javadoc-other is earlier than 0:2.7.1-7jpp.2.el5_4.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14775"/>
      <state state_ref="oval:org.mitre.oval:ste:38395"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139791" version="1" comment="xerces-j2 is earlier than 0:2.7.1-7jpp.2.el5_4.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15189"/>
      <state state_ref="oval:org.mitre.oval:ste:38395"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139583" version="1" comment="xerces-j2-scripts is earlier than 0:2.7.1-7jpp.2.el5_4.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14314"/>
      <state state_ref="oval:org.mitre.oval:ste:38395"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139487" version="1" comment="libpurple is earlier than 0:2.6.3-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:38984"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139470" version="1" comment="finch-devel is earlier than 0:2.6.3-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:38261"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139439" version="1" comment="finch is earlier than 0:2.6.3-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:38984"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139424" version="1" comment="pidgin-perl is earlier than 0:2.6.3-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:38261"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139414" version="1" comment="pidgin is earlier than 0:2.6.3-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:38984"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139413" version="1" comment="libpurple-tcl is earlier than 0:2.6.3-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:38261"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139398" version="1" comment="pidgin is earlier than 0:2.6.3-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:38261"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139361" version="1" comment="finch is earlier than 0:2.6.3-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:38261"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139346" version="1" comment="libpurple-devel is earlier than 0:2.6.3-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:38261"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139333" version="1" comment="pidgin-devel is earlier than 0:2.6.3-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:38984"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139289" version="1" comment="pidgin-devel is earlier than 0:2.6.3-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:38261"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139281" version="1" comment="libpurple is earlier than 0:2.6.3-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:38261"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139223" version="1" comment="finch-devel is earlier than 0:2.6.3-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:38984"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139186" version="1" comment="pidgin-perl is earlier than 0:2.6.3-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:38984"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139125" version="1" comment="libpurple-tcl is earlier than 0:2.6.3-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:38984"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139036" version="1" comment="libpurple-perl is earlier than 0:2.6.3-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:38261"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139014" version="1" comment="libpurple-devel is earlier than 0:2.6.3-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:38984"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138954" version="1" comment="libpurple-perl is earlier than 0:2.6.3-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:38984"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140471" version="1" comment="xulrunner-devel is earlier than 0:1.9.0.6-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:38664"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140453" version="1" comment="nss-tools is earlier than 0:3.12.2.0-3.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:39164"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140433" version="1" comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-4.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:39144"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140424" version="1" comment="firefox is earlier than 0:3.0.6-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:38570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140387" version="1" comment="nss is earlier than 0:3.12.2.0-4.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:39144"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140282" version="1" comment="nss-devel is earlier than 0:3.12.2.0-4.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:39144"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140141" version="1" comment="nss-tools is earlier than 0:3.12.2.0-4.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:39144"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139758" version="1" comment="firefox is earlier than 0:3.0.6-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39384"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139672" version="1" comment="nss-devel is earlier than 0:3.12.2.0-3.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:39164"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139536" version="1" comment="nss is earlier than 0:3.12.2.0-3.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:39164"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139526" version="1" comment="xulrunner is earlier than 0:1.9.0.6-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:38664"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139500" version="1" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.6-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15048"/>
      <state state_ref="oval:org.mitre.oval:ste:38664"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139264" version="1" comment="ipsec-tools is earlier than 0:0.3.3-7.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14216"/>
      <state state_ref="oval:org.mitre.oval:ste:38200"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139200" version="1" comment="ipsec-tools is earlier than 0:0.6.5-9.el5_2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14216"/>
      <state state_ref="oval:org.mitre.oval:ste:39029"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138990" version="1" comment="ipsec-tools is earlier than 0:0.2.5-0.7.rhel3.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14216"/>
      <state state_ref="oval:org.mitre.oval:ste:39026"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140776" version="1" comment="newt is earlier than 0:0.52.2-12.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14373"/>
      <state state_ref="oval:org.mitre.oval:ste:39401"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140745" version="1" comment="newt is earlier than 0:0.51.5-2.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14373"/>
      <state state_ref="oval:org.mitre.oval:ste:38993"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140602" version="1" comment="newt-devel is earlier than 0:0.51.6-10.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14996"/>
      <state state_ref="oval:org.mitre.oval:ste:39306"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140202" version="1" comment="newt-devel is earlier than 0:0.51.5-2.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14996"/>
      <state state_ref="oval:org.mitre.oval:ste:38993"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139993" version="1" comment="newt is earlier than 0:0.51.6-10.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14373"/>
      <state state_ref="oval:org.mitre.oval:ste:39306"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139979" version="1" comment="newt-devel is earlier than 0:0.52.2-12.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14996"/>
      <state state_ref="oval:org.mitre.oval:ste:39401"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139247" version="1" comment="bzip2-devel is earlier than 0:1.0.2-14.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14253"/>
      <state state_ref="oval:org.mitre.oval:ste:39120"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139229" version="1" comment="bzip2-devel is earlier than 0:1.0.3-4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14253"/>
      <state state_ref="oval:org.mitre.oval:ste:39022"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139210" version="1" comment="bzip2-libs is earlier than 0:1.0.2-14.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14666"/>
      <state state_ref="oval:org.mitre.oval:ste:39120"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139209" version="1" comment="bzip2-devel is earlier than 0:1.0.2-12.EL3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14253"/>
      <state state_ref="oval:org.mitre.oval:ste:38436"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139145" version="1" comment="bzip2-libs is earlier than 0:1.0.3-4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14666"/>
      <state state_ref="oval:org.mitre.oval:ste:39022"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139138" version="1" comment="bzip2 is earlier than 0:1.0.2-14.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14678"/>
      <state state_ref="oval:org.mitre.oval:ste:39120"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139137" version="1" comment="bzip2 is earlier than 0:1.0.2-12.EL3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14678"/>
      <state state_ref="oval:org.mitre.oval:ste:38436"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139072" version="1" comment="bzip2 is earlier than 0:1.0.3-4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14678"/>
      <state state_ref="oval:org.mitre.oval:ste:39022"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138972" version="1" comment="bzip2-libs is earlier than 0:1.0.2-12.EL3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14666"/>
      <state state_ref="oval:org.mitre.oval:ste:38436"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139467" version="1" comment="openldap is earlier than 0:2.2.13-8.el4_6.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14650"/>
      <state state_ref="oval:org.mitre.oval:ste:39088"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139465" version="1" comment="openldap-clients is earlier than 0:2.3.27-8.el5_2.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13745"/>
      <state state_ref="oval:org.mitre.oval:ste:39195"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139460" version="1" comment="openldap-devel is earlier than 0:2.2.13-8.el4_6.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14680"/>
      <state state_ref="oval:org.mitre.oval:ste:39088"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139451" version="1" comment="openldap-devel is earlier than 0:2.3.27-8.el5_2.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14680"/>
      <state state_ref="oval:org.mitre.oval:ste:39195"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139420" version="1" comment="openldap-clients is earlier than 0:2.2.13-8.el4_6.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13745"/>
      <state state_ref="oval:org.mitre.oval:ste:39088"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139416" version="1" comment="openldap-servers is earlier than 0:2.2.13-8.el4_6.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14676"/>
      <state state_ref="oval:org.mitre.oval:ste:39088"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139352" version="1" comment="compat-openldap is earlier than 0:2.1.30-8.el4_6.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14705"/>
      <state state_ref="oval:org.mitre.oval:ste:39119"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139341" version="1" comment="compat-openldap is earlier than 0:2.3.27_2.2.29-8.el5_2.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14705"/>
      <state state_ref="oval:org.mitre.oval:ste:38894"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139310" version="1" comment="openldap-servers is earlier than 0:2.3.27-8.el5_2.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14676"/>
      <state state_ref="oval:org.mitre.oval:ste:39195"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139262" version="1" comment="openldap-servers-sql is earlier than 0:2.2.13-8.el4_6.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14387"/>
      <state state_ref="oval:org.mitre.oval:ste:39088"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139240" version="1" comment="openldap is earlier than 0:2.3.27-8.el5_2.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14650"/>
      <state state_ref="oval:org.mitre.oval:ste:39195"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138727" version="1" comment="openldap-servers-sql is earlier than 0:2.3.27-8.el5_2.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14387"/>
      <state state_ref="oval:org.mitre.oval:ste:39195"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139221" version="1" comment="libxml2-devel is earlier than 0:2.5.10-13" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:39075"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139174" version="1" comment="libxml2-devel is earlier than 0:2.6.16-12.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:38910"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139131" version="1" comment="libxml2-python is earlier than 0:2.5.10-13" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:39075"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139100" version="1" comment="libxml2-python is earlier than 0:2.6.26-2.1.2.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:39023"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139099" version="1" comment="libxml2-python is earlier than 0:2.6.16-12.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:38910"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139060" version="1" comment="libxml2 is earlier than 0:2.5.10-13" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:39075"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139011" version="1" comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:39023"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138993" version="1" comment="libxml2 is earlier than 0:2.6.26-2.1.2.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:39023"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138431" version="1" comment="libxml2 is earlier than 0:2.6.16-12.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:38910"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139176" version="1" comment="libxslt-devel is earlier than 0:1.1.17-2.el5_2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15150"/>
      <state state_ref="oval:org.mitre.oval:ste:39067"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139173" version="1" comment="libxslt is earlier than 0:1.1.17-2.el5_2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15147"/>
      <state state_ref="oval:org.mitre.oval:ste:39067"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139133" version="1" comment="libxslt-python is earlier than 0:1.1.17-2.el5_2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14955"/>
      <state state_ref="oval:org.mitre.oval:ste:39067"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138938" version="1" comment="libxslt-python is earlier than 0:1.1.11-1.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14955"/>
      <state state_ref="oval:org.mitre.oval:ste:39018"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138907" version="1" comment="libxslt-devel is earlier than 0:1.1.11-1.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15150"/>
      <state state_ref="oval:org.mitre.oval:ste:39018"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138709" version="1" comment="libxslt is earlier than 0:1.1.11-1.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15147"/>
      <state state_ref="oval:org.mitre.oval:ste:39018"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139472" version="1" comment="yelp is earlier than 0:2.16.0-19.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14764"/>
      <state state_ref="oval:org.mitre.oval:ste:39157"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139446" version="1" comment="firefox is earlier than 0:3.0-2.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:38970"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139443" version="1" comment="xulrunner is earlier than 0:1.9-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:39152"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139385" version="1" comment="devhelp is earlier than 0:0.12-17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14497"/>
      <state state_ref="oval:org.mitre.oval:ste:38878"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139358" version="1" comment="xulrunner-devel-unstable is earlier than 0:1.9-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15048"/>
      <state state_ref="oval:org.mitre.oval:ste:39152"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139300" version="1" comment="devhelp-devel is earlier than 0:0.12-17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14520"/>
      <state state_ref="oval:org.mitre.oval:ste:38878"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139166" version="1" comment="firefox is earlier than 0:3.0-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138773" version="1" comment="xulrunner-devel is earlier than 0:1.9-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:39152"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141094" version="1" comment="cyrus-imapd-perl is earlier than 0:2.3.7-2.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14774"/>
      <state state_ref="oval:org.mitre.oval:ste:39436"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141061" version="1" comment="cyrus-imapd-devel is earlier than 0:2.2.12-10.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3584"/>
      <state state_ref="oval:org.mitre.oval:ste:39544"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141048" version="1" comment="cyrus-imapd is earlier than 0:2.3.7-2.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3854"/>
      <state state_ref="oval:org.mitre.oval:ste:39436"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141039" version="1" comment="cyrus-imapd-nntp is earlier than 0:2.2.12-10.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14271"/>
      <state state_ref="oval:org.mitre.oval:ste:39544"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140932" version="1" comment="perl-Cyrus is earlier than 0:2.2.12-10.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14532"/>
      <state state_ref="oval:org.mitre.oval:ste:39544"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140841" version="1" comment="cyrus-imapd is earlier than 0:2.2.12-10.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3854"/>
      <state state_ref="oval:org.mitre.oval:ste:39544"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140638" version="1" comment="cyrus-imapd-utils is earlier than 0:2.3.7-2.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14555"/>
      <state state_ref="oval:org.mitre.oval:ste:39436"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140528" version="1" comment="cyrus-imapd-murder is earlier than 0:2.2.12-10.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14681"/>
      <state state_ref="oval:org.mitre.oval:ste:39544"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140157" version="1" comment="cyrus-imapd-devel is earlier than 0:2.3.7-2.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3584"/>
      <state state_ref="oval:org.mitre.oval:ste:39436"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140102" version="1" comment="cyrus-imapd-utils is earlier than 0:2.2.12-10.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14555"/>
      <state state_ref="oval:org.mitre.oval:ste:39544"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140747" version="1" comment="gnutls is earlier than 0:1.4.1-3.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14386"/>
      <state state_ref="oval:org.mitre.oval:ste:38884"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140653" version="1" comment="gnutls-devel is earlier than 0:1.4.1-3.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14558"/>
      <state state_ref="oval:org.mitre.oval:ste:38884"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140326" version="1" comment="gnutls-utils is earlier than 0:1.4.1-3.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15003"/>
      <state state_ref="oval:org.mitre.oval:ste:38884"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139073" version="1" comment="wireshark-gnome is earlier than 0:1.0.3-EL3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14663"/>
      <state state_ref="oval:org.mitre.oval:ste:38999"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138974" version="1" comment="wireshark is earlier than 0:1.0.3-3.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14711"/>
      <state state_ref="oval:org.mitre.oval:ste:38976"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138902" version="1" comment="wireshark-gnome is earlier than 0:1.0.3-3.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14663"/>
      <state state_ref="oval:org.mitre.oval:ste:38976"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138870" version="1" comment="wireshark is earlier than 0:1.0.3-EL3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14711"/>
      <state state_ref="oval:org.mitre.oval:ste:38999"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138714" version="1" comment="wireshark is earlier than 0:1.0.3-4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14711"/>
      <state state_ref="oval:org.mitre.oval:ste:39022"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138182" version="1" comment="wireshark-gnome is earlier than 0:1.0.3-4.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14663"/>
      <state state_ref="oval:org.mitre.oval:ste:39022"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139273" version="1" comment="firefox is earlier than 0:3.0.2-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:38495"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139250" version="1" comment="nss-tools is earlier than 0:3.12.1.1-1.el5.centos.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:39008"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139242" version="1" comment="devhelp-devel is earlier than 0:0.12-19.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14520"/>
      <state state_ref="oval:org.mitre.oval:ste:39000"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139178" version="1" comment="firefox is earlier than 0:3.0.2-3.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39046"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139177" version="1" comment="nss is earlier than 0:3.12.1.1-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:38923"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139171" version="1" comment="xulrunner is earlier than 0:1.9.0.2-5.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:39089"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139160" version="1" comment="xulrunner-devel is earlier than 0:1.9.0.2-5.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:39089"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139127" version="1" comment="nss is earlier than 0:3.12.1.1-1.el5.centos.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:39008"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139109" version="1" comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:38923"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139097" version="1" comment="devhelp is earlier than 0:0.12-19.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14497"/>
      <state state_ref="oval:org.mitre.oval:ste:39000"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139092" version="1" comment="nss-devel is earlier than 0:3.12.1.1-1.el5.centos.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:39008"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139045" version="1" comment="yelp is earlier than 0:2.16.0-21.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14764"/>
      <state state_ref="oval:org.mitre.oval:ste:38633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139018" version="1" comment="firefox is earlier than 0:3.0.2-3.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39078"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138911" version="1" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.2-5.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15048"/>
      <state state_ref="oval:org.mitre.oval:ste:39089"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138903" version="1" comment="nss-devel is earlier than 0:3.12.1.1-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:38923"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138708" version="1" comment="nss-tools is earlier than 0:3.12.1.1-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:38923"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138700" version="1" comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-1.el5.centos.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:39008"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140531" version="1" comment="bind is earlier than 30:9.2.4-30.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:39395"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140523" version="1" comment="bind-chroot is earlier than 30:9.2.4-30.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:39395"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140518" version="1" comment="bind-libs is earlier than 30:9.2.4-30.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:39395"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140505" version="1" comment="bind-chroot is earlier than 30:9.3.4-6.0.3.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:38830"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140497" version="1" comment="bind-devel is earlier than 30:9.3.4-6.0.3.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:38830"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140478" version="1" comment="bind-libbind-devel is earlier than 30:9.3.4-6.0.3.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14729"/>
      <state state_ref="oval:org.mitre.oval:ste:38830"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140465" version="1" comment="bind-utils is earlier than 30:9.2.4-30.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:39395"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140398" version="1" comment="bind is earlier than 30:9.2.4-23.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:39290"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140372" version="1" comment="bind is earlier than 30:9.3.4-6.0.3.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:38830"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140347" version="1" comment="bind-devel is earlier than 30:9.2.4-23.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:39290"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140333" version="1" comment="bind-utils is earlier than 30:9.2.4-23.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:39290"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140317" version="1" comment="caching-nameserver is earlier than 30:9.3.4-6.0.3.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14701"/>
      <state state_ref="oval:org.mitre.oval:ste:38830"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140295" version="1" comment="bind-sdb is earlier than 30:9.3.4-6.0.3.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:38830"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140179" version="1" comment="bind-libs is earlier than 30:9.3.4-6.0.3.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:38830"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140146" version="1" comment="bind-utils is earlier than 30:9.3.4-6.0.3.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:38830"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139958" version="1" comment="bind-devel is earlier than 30:9.2.4-30.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:39395"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139734" version="1" comment="bind-libs is earlier than 30:9.2.4-23.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:39290"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139550" version="1" comment="bind-chroot is earlier than 30:9.2.4-23.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:39290"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139313" version="1" comment="kernel-headers is earlier than 0:2.6.18-92.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:39028"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139308" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:39028"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139294" version="1" comment="kernel-debug is earlier than 0:2.6.18-92.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:39028"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139284" version="1" comment="kernel-doc is earlier than 0:2.6.18-92.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:39028"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139238" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:39028"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139234" version="1" comment="kernel-PAE is earlier than 0:2.6.18-92.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:39028"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139197" version="1" comment="kernel-xen is earlier than 0:2.6.18-92.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:39028"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139046" version="1" comment="kernel is earlier than 0:2.6.18-92.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:39028"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138980" version="1" comment="kernel-devel is earlier than 0:2.6.18-92.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:39028"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138332" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.10.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:39028"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139447" version="1" comment="ruby is earlier than 0:1.8.1-7.el4_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14305"/>
      <state state_ref="oval:org.mitre.oval:ste:38826"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139374" version="1" comment="ruby-libs is earlier than 0:1.8.1-7.el4_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14388"/>
      <state state_ref="oval:org.mitre.oval:ste:38826"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139292" version="1" comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14446"/>
      <state state_ref="oval:org.mitre.oval:ste:39025"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139269" version="1" comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14273"/>
      <state state_ref="oval:org.mitre.oval:ste:39025"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139261" version="1" comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14461"/>
      <state state_ref="oval:org.mitre.oval:ste:39025"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139228" version="1" comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14273"/>
      <state state_ref="oval:org.mitre.oval:ste:38826"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139214" version="1" comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14244"/>
      <state state_ref="oval:org.mitre.oval:ste:39025"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139140" version="1" comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14388"/>
      <state state_ref="oval:org.mitre.oval:ste:39025"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139055" version="1" comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14777"/>
      <state state_ref="oval:org.mitre.oval:ste:39025"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139026" version="1" comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14380"/>
      <state state_ref="oval:org.mitre.oval:ste:39025"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138908" version="1" comment="ruby-devel is earlier than 0:1.8.1-7.el4_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14187"/>
      <state state_ref="oval:org.mitre.oval:ste:38826"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138893" version="1" comment="ruby-docs is earlier than 0:1.8.1-7.el4_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14446"/>
      <state state_ref="oval:org.mitre.oval:ste:38826"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138834" version="1" comment="ruby is earlier than 0:1.8.5-5.el5_2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14305"/>
      <state state_ref="oval:org.mitre.oval:ste:39025"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138779" version="1" comment="ruby-mode is earlier than 0:1.8.1-7.el4_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14380"/>
      <state state_ref="oval:org.mitre.oval:ste:38826"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138737" version="1" comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14187"/>
      <state state_ref="oval:org.mitre.oval:ste:39025"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138487" version="1" comment="irb is earlier than 0:1.8.1-7.el4_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13649"/>
      <state state_ref="oval:org.mitre.oval:ste:38826"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140464" version="1" comment="curl is earlier than 0:7.15.5-2.1.el5_3.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14575"/>
      <state state_ref="oval:org.mitre.oval:ste:39169"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140380" version="1" comment="curl is earlier than 0:7.12.1-11.1.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14575"/>
      <state state_ref="oval:org.mitre.oval:ste:39255"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140331" version="1" comment="curl-devel is earlier than 0:7.15.5-2.1.el5_3.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14469"/>
      <state state_ref="oval:org.mitre.oval:ste:39169"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140277" version="1" comment="curl-devel is earlier than 0:7.12.1-11.1.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14469"/>
      <state state_ref="oval:org.mitre.oval:ste:39255"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140258" version="1" comment="curl-devel is earlier than 0:7.10.6-9.rhel3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14469"/>
      <state state_ref="oval:org.mitre.oval:ste:38939"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140137" version="1" comment="curl is earlier than 0:7.10.6-9.rhel3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14575"/>
      <state state_ref="oval:org.mitre.oval:ste:38939"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140625" version="1" comment="enscript is earlier than 0:1.6.4-4.1.1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14574"/>
      <state state_ref="oval:org.mitre.oval:ste:38853"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139213" version="1" comment="libtiff is earlier than 0:3.8.2-7.el5_2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14341"/>
      <state state_ref="oval:org.mitre.oval:ste:38909"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139087" version="1" comment="libtiff-devel is earlier than 0:3.8.2-7.el5_2.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14174"/>
      <state state_ref="oval:org.mitre.oval:ste:38909"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140450" version="1" comment="kernel-debug is earlier than 0:2.6.18-128.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:38904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140373" version="1" comment="kernel-headers is earlier than 0:2.6.18-128.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:38904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140364" version="1" comment="kernel-xen is earlier than 0:2.6.18-128.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:38904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140305" version="1" comment="kernel-PAE is earlier than 0:2.6.18-128.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:38904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140303" version="1" comment="kernel-doc is earlier than 0:2.6.18-128.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:38904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140275" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:38904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140231" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:38904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140184" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:38904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139986" version="1" comment="kernel is earlier than 0:2.6.18-128.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:38904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139808" version="1" comment="kernel-devel is earlier than 0:2.6.18-128.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:38904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141064" version="1" comment="libicu-devel is earlier than 0:3.6-5.11.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14587"/>
      <state state_ref="oval:org.mitre.oval:ste:39036"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141062" version="1" comment="libicu is earlier than 0:3.6-5.11.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14735"/>
      <state state_ref="oval:org.mitre.oval:ste:39036"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141055" version="1" comment="icu is earlier than 0:3.6-5.11.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14949"/>
      <state state_ref="oval:org.mitre.oval:ste:39036"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140904" version="1" comment="libicu-doc is earlier than 0:3.6-5.11.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14890"/>
      <state state_ref="oval:org.mitre.oval:ste:39036"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140753" version="1" comment="lynx is earlier than 0:2.8.5-28.1.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14519"/>
      <state state_ref="oval:org.mitre.oval:ste:39350"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140604" version="1" comment="lynx is earlier than 0:2.8.5-11.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14519"/>
      <state state_ref="oval:org.mitre.oval:ste:39175"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140386" version="1" comment="lynx is earlier than 0:2.8.5-18.2.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14519"/>
      <state state_ref="oval:org.mitre.oval:ste:39354"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140905" version="1" comment="libxml2 is earlier than 0:2.5.10-15" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:39242"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140897" version="1" comment="libxml2 is earlier than 0:2.6.16-12.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:39404"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140887" version="1" comment="libxml2-python is earlier than 0:2.5.10-15" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:39242"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140882" version="1" comment="libxml2-python is earlier than 0:2.6.16-12.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:39404"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140843" version="1" comment="libxml2-devel is earlier than 0:2.6.16-12.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:39404"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140788" version="1" comment="libxml2-python is earlier than 0:2.6.26-2.1.2.8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:39417"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140698" version="1" comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:39417"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140644" version="1" comment="libxml-devel is earlier than 1:1.8.17-9.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14286"/>
      <state state_ref="oval:org.mitre.oval:ste:39394"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140639" version="1" comment="libxml2 is earlier than 0:2.6.26-2.1.2.8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:39417"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140489" version="1" comment="libxml2-devel is earlier than 0:2.5.10-15" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:39242"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140195" version="1" comment="libxml is earlier than 0:1.8.17-9.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14454"/>
      <state state_ref="oval:org.mitre.oval:ste:38950"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140476" version="1" comment="systemtap is earlier than 0:0.6.2-2.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15026"/>
      <state state_ref="oval:org.mitre.oval:ste:39328"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140457" version="1" comment="systemtap-testsuite is earlier than 0:0.6.2-2.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14298"/>
      <state state_ref="oval:org.mitre.oval:ste:39328"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140449" version="1" comment="systemtap-client is earlier than 0:0.7.2-3.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15212"/>
      <state state_ref="oval:org.mitre.oval:ste:39257"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140425" version="1" comment="systemtap-server is earlier than 0:0.7.2-3.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14954"/>
      <state state_ref="oval:org.mitre.oval:ste:39257"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140343" version="1" comment="systemtap is earlier than 0:0.7.2-3.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15026"/>
      <state state_ref="oval:org.mitre.oval:ste:39257"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140219" version="1" comment="systemtap-runtime is earlier than 0:0.6.2-2.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15292"/>
      <state state_ref="oval:org.mitre.oval:ste:39328"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140113" version="1" comment="systemtap-runtime is earlier than 0:0.7.2-3.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15292"/>
      <state state_ref="oval:org.mitre.oval:ste:39257"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140059" version="1" comment="systemtap-testsuite is earlier than 0:0.7.2-3.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14298"/>
      <state state_ref="oval:org.mitre.oval:ste:39257"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140597" version="1" comment="gfs2-utils is earlier than 0:0.1.62-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15064"/>
      <state state_ref="oval:org.mitre.oval:ste:39300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141163" version="1" comment="pango-devel is earlier than 0:1.6.0-14.4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15280"/>
      <state state_ref="oval:org.mitre.oval:ste:39211"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141156" version="1" comment="pango is earlier than 0:1.14.9-5.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15101"/>
      <state state_ref="oval:org.mitre.oval:ste:39583"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141100" version="1" comment="pango-devel is earlier than 0:1.14.9-5.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15280"/>
      <state state_ref="oval:org.mitre.oval:ste:39583"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141059" version="1" comment="pango-devel is earlier than 0:1.14.9-5.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15280"/>
      <state state_ref="oval:org.mitre.oval:ste:39549"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140920" version="1" comment="evolution28-pango-devel is earlier than 0:1.14.9-11.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15030"/>
      <state state_ref="oval:org.mitre.oval:ste:38780"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140809" version="1" comment="pango is earlier than 0:1.2.5-8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15101"/>
      <state state_ref="oval:org.mitre.oval:ste:39449"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140726" version="1" comment="pango-devel is earlier than 0:1.2.5-8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15280"/>
      <state state_ref="oval:org.mitre.oval:ste:39449"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140598" version="1" comment="pango is earlier than 0:1.6.0-14.4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15101"/>
      <state state_ref="oval:org.mitre.oval:ste:39211"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140524" version="1" comment="evolution28-pango is earlier than 0:1.14.9-11.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15094"/>
      <state state_ref="oval:org.mitre.oval:ste:38780"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140165" version="1" comment="pango is earlier than 0:1.14.9-5.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15101"/>
      <state state_ref="oval:org.mitre.oval:ste:39549"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140805" version="1" comment="postgresql-jdbc is earlier than 0:7.4.26-1.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14547"/>
      <state state_ref="oval:org.mitre.oval:ste:39377"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140789" version="1" comment="postgresql-contrib is earlier than 0:7.4.26-1.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14293"/>
      <state state_ref="oval:org.mitre.oval:ste:39377"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140775" version="1" comment="postgresql-test is earlier than 0:7.4.26-1.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14367"/>
      <state state_ref="oval:org.mitre.oval:ste:39377"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140770" version="1" comment="postgresql-python is earlier than 0:7.4.26-1.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14546"/>
      <state state_ref="oval:org.mitre.oval:ste:39377"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140742" version="1" comment="postgresql-pl is earlier than 0:7.4.26-1.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14537"/>
      <state state_ref="oval:org.mitre.oval:ste:39377"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140740" version="1" comment="postgresql-server is earlier than 0:7.4.26-1.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14158"/>
      <state state_ref="oval:org.mitre.oval:ste:39377"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140713" version="1" comment="postgresql-docs is earlier than 0:7.4.26-1.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14365"/>
      <state state_ref="oval:org.mitre.oval:ste:39377"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140709" version="1" comment="postgresql-libs is earlier than 0:8.1.18-2.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14383"/>
      <state state_ref="oval:org.mitre.oval:ste:38613"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140652" version="1" comment="postgresql-python is earlier than 0:8.1.18-2.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14546"/>
      <state state_ref="oval:org.mitre.oval:ste:38613"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140651" version="1" comment="postgresql-server is earlier than 0:8.1.18-2.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14158"/>
      <state state_ref="oval:org.mitre.oval:ste:38613"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140622" version="1" comment="postgresql-pl is earlier than 0:8.1.18-2.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14537"/>
      <state state_ref="oval:org.mitre.oval:ste:38613"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140611" version="1" comment="postgresql-libs is earlier than 0:7.4.26-1.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14383"/>
      <state state_ref="oval:org.mitre.oval:ste:39377"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140606" version="1" comment="postgresql-test is earlier than 0:8.1.18-2.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14367"/>
      <state state_ref="oval:org.mitre.oval:ste:38613"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140601" version="1" comment="postgresql-contrib is earlier than 0:8.1.18-2.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14293"/>
      <state state_ref="oval:org.mitre.oval:ste:38613"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140554" version="1" comment="postgresql-docs is earlier than 0:8.1.18-2.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14365"/>
      <state state_ref="oval:org.mitre.oval:ste:38613"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140506" version="1" comment="postgresql-tcl is earlier than 0:7.4.26-1.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14486"/>
      <state state_ref="oval:org.mitre.oval:ste:39377"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140499" version="1" comment="postgresql-devel is earlier than 0:8.1.18-2.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14290"/>
      <state state_ref="oval:org.mitre.oval:ste:38613"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140485" version="1" comment="postgresql is earlier than 0:8.1.18-2.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14586"/>
      <state state_ref="oval:org.mitre.oval:ste:38613"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140239" version="1" comment="postgresql is earlier than 0:7.4.26-1.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14586"/>
      <state state_ref="oval:org.mitre.oval:ste:39377"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140115" version="1" comment="postgresql-devel is earlier than 0:7.4.26-1.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14290"/>
      <state state_ref="oval:org.mitre.oval:ste:39377"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140005" version="1" comment="postgresql-tcl is earlier than 0:8.1.18-2.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14486"/>
      <state state_ref="oval:org.mitre.oval:ste:38613"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140301" version="1" comment="openswan is earlier than 0:2.6.14-1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14994"/>
      <state state_ref="oval:org.mitre.oval:ste:38706"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139535" version="1" comment="openswan-doc is earlier than 0:2.6.14-1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15278"/>
      <state state_ref="oval:org.mitre.oval:ste:38706"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139095" version="1" comment="xen-devel is earlier than 0:3.0.3-64.el5_2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14567"/>
      <state state_ref="oval:org.mitre.oval:ste:38598"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138896" version="1" comment="xen is earlier than 0:3.0.3-64.el5_2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14646"/>
      <state state_ref="oval:org.mitre.oval:ste:38598"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138274" version="1" comment="xen-libs is earlier than 0:3.0.3-64.el5_2.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14810"/>
      <state state_ref="oval:org.mitre.oval:ste:38598"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140590" version="1" comment="lftp is earlier than 0:3.7.11-4.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13476"/>
      <state state_ref="oval:org.mitre.oval:ste:39370"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140696" version="1" comment="elinks is earlier than 0:0.9.2-4.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14684"/>
      <state state_ref="oval:org.mitre.oval:ste:39406"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140395" version="1" comment="elinks is earlier than 0:0.11.1-6.el5_4.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14684"/>
      <state state_ref="oval:org.mitre.oval:ste:38925"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140492" version="1" comment="ntp is earlier than 0:4.2.2p1-9.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14371"/>
      <state state_ref="oval:org.mitre.oval:ste:39107"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140430" version="1" comment="ntp is earlier than 0:4.2.2p1-9.el5.centos.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14371"/>
      <state state_ref="oval:org.mitre.oval:ste:39307"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139913" version="1" comment="ntp is earlier than 0:4.2.0.a.20040617-8.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14371"/>
      <state state_ref="oval:org.mitre.oval:ste:39296"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140692" version="1" comment="poppler is earlier than 0:0.5.4-4.4.el5_4.11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14394"/>
      <state state_ref="oval:org.mitre.oval:ste:39238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140687" version="1" comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_4.11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14640"/>
      <state state_ref="oval:org.mitre.oval:ste:39238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140605" version="1" comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_4.11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14966"/>
      <state state_ref="oval:org.mitre.oval:ste:39238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140241" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.7.b09.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:39371"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140192" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.7.b09.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:39371"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140136" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.7.b09.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:39371"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140063" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.7.b09.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:39371"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139552" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.7.b09.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:39371"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139396" version="1" comment="kdegraphics is earlier than 7:3.5.4-15.el5_4.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14241"/>
      <state state_ref="oval:org.mitre.oval:ste:39214"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138729" version="1" comment="kdegraphics-devel is earlier than 7:3.5.4-15.el5_4.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14596"/>
      <state state_ref="oval:org.mitre.oval:ste:39214"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140269" version="1" comment="gstreamer-plugins-good is earlier than 0:0.10.9-1.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15182"/>
      <state state_ref="oval:org.mitre.oval:ste:39259"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139677" version="1" comment="gstreamer-plugins-good-devel is earlier than 0:0.10.9-1.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14946"/>
      <state state_ref="oval:org.mitre.oval:ste:39259"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141101" version="1" comment="wireshark is earlier than 0:1.0.8-EL3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14711"/>
      <state state_ref="oval:org.mitre.oval:ste:39445"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140895" version="1" comment="wireshark is earlier than 0:1.0.8-1.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14711"/>
      <state state_ref="oval:org.mitre.oval:ste:39145"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140892" version="1" comment="wireshark-gnome is earlier than 0:1.0.8-EL3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14663"/>
      <state state_ref="oval:org.mitre.oval:ste:39445"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140779" version="1" comment="wireshark-gnome is earlier than 0:1.0.8-1.el4_8.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14663"/>
      <state state_ref="oval:org.mitre.oval:ste:39145"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140700" version="1" comment="wireshark-gnome is earlier than 0:1.0.8-1.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14663"/>
      <state state_ref="oval:org.mitre.oval:ste:39252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140402" version="1" comment="wireshark is earlier than 0:1.0.8-1.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14711"/>
      <state state_ref="oval:org.mitre.oval:ste:39252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140815" version="1" comment="mysql-bench is earlier than 0:5.0.77-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14400"/>
      <state state_ref="oval:org.mitre.oval:ste:39039"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140684" version="1" comment="mysql is earlier than 0:5.0.77-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14355"/>
      <state state_ref="oval:org.mitre.oval:ste:39039"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140573" version="1" comment="mysql-server is earlier than 0:5.0.77-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14342"/>
      <state state_ref="oval:org.mitre.oval:ste:39039"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140567" version="1" comment="mysql-test is earlier than 0:5.0.77-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14941"/>
      <state state_ref="oval:org.mitre.oval:ste:39039"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139909" version="1" comment="mysql-devel is earlier than 0:5.0.77-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14481"/>
      <state state_ref="oval:org.mitre.oval:ste:39039"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138566" version="1" comment="nfs-utils is earlier than 1:1.0.9-35z.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14333"/>
      <state state_ref="oval:org.mitre.oval:ste:38703"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141014" version="1" comment="libtiff is earlier than 0:3.8.2-7.el5_3.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14341"/>
      <state state_ref="oval:org.mitre.oval:ste:38905"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140923" version="1" comment="libtiff is earlier than 0:3.5.7-33.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14341"/>
      <state state_ref="oval:org.mitre.oval:ste:39385"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140854" version="1" comment="libtiff-devel is earlier than 0:3.5.7-33.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14174"/>
      <state state_ref="oval:org.mitre.oval:ste:39385"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140723" version="1" comment="libtiff-devel is earlier than 0:3.8.2-7.el5_3.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14174"/>
      <state state_ref="oval:org.mitre.oval:ste:38905"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140596" version="1" comment="libtiff-devel is earlier than 0:3.6.1-12.el4_8.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14174"/>
      <state state_ref="oval:org.mitre.oval:ste:39518"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140043" version="1" comment="libtiff is earlier than 0:3.6.1-12.el4_8.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14341"/>
      <state state_ref="oval:org.mitre.oval:ste:39518"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140829" version="1" comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14640"/>
      <state state_ref="oval:org.mitre.oval:ste:38585"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140821" version="1" comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14394"/>
      <state state_ref="oval:org.mitre.oval:ste:38585"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140752" version="1" comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14966"/>
      <state state_ref="oval:org.mitre.oval:ste:38585"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140216" version="1" comment="kernel-xen is earlier than 0:2.6.18-164.9.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:39072"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140207" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-164.9.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:39072"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140203" version="1" comment="kernel is earlier than 0:2.6.18-164.9.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:39072"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140153" version="1" comment="kernel-debug is earlier than 0:2.6.18-164.9.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:39072"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140103" version="1" comment="kernel-headers is earlier than 0:2.6.18-164.9.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:39072"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139930" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-164.9.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:39072"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139851" version="1" comment="kernel-PAE is earlier than 0:2.6.18-164.9.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:39072"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139555" version="1" comment="kernel-devel is earlier than 0:2.6.18-164.9.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:39072"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139448" version="1" comment="kernel-doc is earlier than 0:2.6.18-164.9.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:39072"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139254" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-164.9.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:39072"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140388" version="1" comment="mod_auth_mysql is earlier than 1:3.0.0-3.2.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14493"/>
      <state state_ref="oval:org.mitre.oval:ste:39126"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139143" version="1" comment="yum-rhn-plugin is earlier than 0:0.5.3-12.el5_2.9" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15021"/>
      <state state_ref="oval:org.mitre.oval:ste:38843"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140189" version="1" comment="acpid is earlier than 0:1.0.3-2.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14820"/>
      <state state_ref="oval:org.mitre.oval:ste:39221"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139783" version="1" comment="acpid is earlier than 0:1.0.2-4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14820"/>
      <state state_ref="oval:org.mitre.oval:ste:39179"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139311" version="1" comment="acpid is earlier than 0:1.0.4-7.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14820"/>
      <state state_ref="oval:org.mitre.oval:ste:39266"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141096" version="1" comment="httpd-manual is earlier than 0:2.2.3-22.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:39330"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140942" version="1" comment="httpd-manual is earlier than 0:2.2.3-22.el5.centos.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:39469"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140715" version="1" comment="httpd is earlier than 0:2.2.3-22.el5.centos.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:39469"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140704" version="1" comment="httpd-devel is earlier than 0:2.2.3-22.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14256"/>
      <state state_ref="oval:org.mitre.oval:ste:39330"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140508" version="1" comment="httpd is earlier than 0:2.2.3-22.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:39330"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140501" version="1" comment="mod_ssl is earlier than 0:2.2.3-22.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:39330"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140150" version="1" comment="mod_ssl is earlier than 0:2.2.3-22.el5.centos.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:39469"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140112" version="1" comment="httpd-devel is earlier than 0:2.2.3-22.el5.centos.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14256"/>
      <state state_ref="oval:org.mitre.oval:ste:39469"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140405" version="1" comment="kernel-debug is earlier than 0:2.6.18-128.1.6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:39237"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140391" version="1" comment="kernel-debug-debuginfo is earlier than 0:2.6.18-128.1.6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42590"/>
      <state state_ref="oval:org.mitre.oval:ste:39237"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140371" version="1" comment="kernel-debuginfo-common is earlier than 0:2.6.18-128.1.6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14853"/>
      <state state_ref="oval:org.mitre.oval:ste:39237"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140369" version="1" comment="kernel is earlier than 0:2.6.18-128.1.6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:39237"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140344" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:39237"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140325" version="1" comment="kernel-xen-debuginfo is earlier than 0:2.6.18-128.1.6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42411"/>
      <state state_ref="oval:org.mitre.oval:ste:39237"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140290" version="1" comment="kernel-PAE-debuginfo is earlier than 0:2.6.18-128.1.6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42166"/>
      <state state_ref="oval:org.mitre.oval:ste:39237"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140244" version="1" comment="kernel-debuginfo is earlier than 0:2.6.18-128.1.6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42117"/>
      <state state_ref="oval:org.mitre.oval:ste:39237"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140225" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:39237"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140191" version="1" comment="kernel-PAE is earlier than 0:2.6.18-128.1.6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:39237"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140174" version="1" comment="kernel-headers is earlier than 0:2.6.18-128.1.6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:39237"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140126" version="1" comment="kernel-xen is earlier than 0:2.6.18-128.1.6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:39237"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139799" version="1" comment="kernel-devel is earlier than 0:2.6.18-128.1.6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:39237"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139624" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:39237"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139475" version="1" comment="kernel-doc is earlier than 0:2.6.18-128.1.6.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:39237"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139485" version="1" comment="bind-devel is earlier than 30:9.3.4-6.0.1.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:39063"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139484" version="1" comment="bind-devel is earlier than 30:9.3.4-6.0.2.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:38568"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139480" version="1" comment="selinux-policy-targeted is earlier than 0:2.4.6-137.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14731"/>
      <state state_ref="oval:org.mitre.oval:ste:38937"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139477" version="1" comment="selinux-policy-mls is earlier than 0:2.4.6-137.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15143"/>
      <state state_ref="oval:org.mitre.oval:ste:38937"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139469" version="1" comment="bind-utils is earlier than 30:9.2.4-22.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:39104"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139421" version="1" comment="selinux-policy-strict is earlier than 0:2.4.6-137.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14914"/>
      <state state_ref="oval:org.mitre.oval:ste:38937"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139418" version="1" comment="bind-devel is earlier than 30:9.2.4-22.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:39104"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139404" version="1" comment="bind-libs is earlier than 30:9.3.4-6.0.1.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:39063"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139387" version="1" comment="bind-sdb is earlier than 30:9.3.4-6.0.1.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:39063"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139381" version="1" comment="bind is earlier than 30:9.3.4-6.0.1.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:39063"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139356" version="1" comment="selinux-policy-strict is earlier than 0:2.4.6-137.1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14914"/>
      <state state_ref="oval:org.mitre.oval:ste:38737"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139330" version="1" comment="bind-chroot is earlier than 30:9.2.4-22.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:39104"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139328" version="1" comment="selinux-policy is earlier than 0:2.4.6-137.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15111"/>
      <state state_ref="oval:org.mitre.oval:ste:38937"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139306" version="1" comment="bind-libbind-devel is earlier than 30:9.3.4-6.0.2.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14729"/>
      <state state_ref="oval:org.mitre.oval:ste:38568"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139293" version="1" comment="selinux-policy-targeted-sources is earlier than 0:1.17.30-2.150.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14929"/>
      <state state_ref="oval:org.mitre.oval:ste:39079"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139291" version="1" comment="selinux-policy-devel is earlier than 0:2.4.6-137.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15077"/>
      <state state_ref="oval:org.mitre.oval:ste:38937"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139260" version="1" comment="bind is earlier than 30:9.3.4-6.0.2.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:38568"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139251" version="1" comment="caching-nameserver is earlier than 30:9.3.4-6.0.2.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14701"/>
      <state state_ref="oval:org.mitre.oval:ste:38568"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139239" version="1" comment="bind-devel is earlier than 30:9.2.4-28.0.1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:38623"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139224" version="1" comment="bind-chroot is earlier than 30:9.2.4-28.0.1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:38623"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139216" version="1" comment="caching-nameserver is earlier than 30:9.3.4-6.0.1.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14701"/>
      <state state_ref="oval:org.mitre.oval:ste:39063"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139208" version="1" comment="selinux-policy is earlier than 0:2.4.6-137.1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15111"/>
      <state state_ref="oval:org.mitre.oval:ste:38737"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139207" version="1" comment="bind-libs is earlier than 30:9.2.4-28.0.1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:38623"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139195" version="1" comment="selinux-policy-mls is earlier than 0:2.4.6-137.1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15143"/>
      <state state_ref="oval:org.mitre.oval:ste:38737"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139192" version="1" comment="bind-sdb is earlier than 30:9.3.4-6.0.2.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:38568"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139183" version="1" comment="bind-chroot is earlier than 30:9.3.4-6.0.1.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:39063"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139175" version="1" comment="bind-utils is earlier than 30:9.3.4-6.0.1.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:39063"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139168" version="1" comment="bind-chroot is earlier than 30:9.3.4-6.0.2.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:38568"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139116" version="1" comment="selinux-policy-devel is earlier than 0:2.4.6-137.1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15077"/>
      <state state_ref="oval:org.mitre.oval:ste:38737"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139104" version="1" comment="selinux-policy-targeted is earlier than 0:2.4.6-137.1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14731"/>
      <state state_ref="oval:org.mitre.oval:ste:38737"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139096" version="1" comment="bind is earlier than 30:9.2.4-22.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:39104"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139070" version="1" comment="bind is earlier than 30:9.2.4-28.0.1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:38623"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139035" version="1" comment="bind-libs is earlier than 30:9.3.4-6.0.2.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:38568"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139033" version="1" comment="bind-libbind-devel is earlier than 30:9.3.4-6.0.1.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14729"/>
      <state state_ref="oval:org.mitre.oval:ste:39063"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138935" version="1" comment="bind-utils is earlier than 30:9.3.4-6.0.2.P1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:38568"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138871" version="1" comment="selinux-policy-targeted is earlier than 0:1.17.30-2.150.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14731"/>
      <state state_ref="oval:org.mitre.oval:ste:39079"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138788" version="1" comment="bind-utils is earlier than 30:9.2.4-28.0.1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:38623"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138746" version="1" comment="bind-libs is earlier than 30:9.2.4-22.el3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:39104"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140456" version="1" comment="xen-devel is earlier than 0:3.0.3-64.el5_2.9" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14567"/>
      <state state_ref="oval:org.mitre.oval:ste:39323"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140114" version="1" comment="xen is earlier than 0:3.0.3-64.el5_2.9" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14646"/>
      <state state_ref="oval:org.mitre.oval:ste:39323"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139584" version="1" comment="xen-libs is earlier than 0:3.0.3-64.el5_2.9" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14810"/>
      <state state_ref="oval:org.mitre.oval:ste:39323"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139479" version="1" comment="pidgin-perl is earlier than 0:2.6.2-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:38564"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139471" version="1" comment="pidgin-perl is earlier than 0:2.6.2-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:38811"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139433" version="1" comment="libpurple-tcl is earlier than 0:2.6.2-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:38811"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139415" version="1" comment="finch-devel is earlier than 0:2.6.2-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:38811"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139357" version="1" comment="finch is earlier than 0:2.6.2-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:38564"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139305" version="1" comment="finch is earlier than 0:2.6.2-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:38811"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139268" version="1" comment="libpurple is earlier than 0:2.6.2-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:38564"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139252" version="1" comment="finch-devel is earlier than 0:2.6.2-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:38564"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139249" version="1" comment="libpurple-perl is earlier than 0:2.6.2-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:38564"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139235" version="1" comment="libpurple-devel is earlier than 0:2.6.2-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:38564"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139152" version="1" comment="libpurple-tcl is earlier than 0:2.6.2-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:38564"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139150" version="1" comment="pidgin is earlier than 0:2.6.2-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:38564"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139135" version="1" comment="libpurple-perl is earlier than 0:2.6.2-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:38811"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139110" version="1" comment="pidgin-devel is earlier than 0:2.6.2-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:38811"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139103" version="1" comment="pidgin is earlier than 0:2.6.2-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:38811"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138800" version="1" comment="libpurple is earlier than 0:2.6.2-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:38811"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138652" version="1" comment="pidgin-devel is earlier than 0:2.6.2-2.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:38564"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138489" version="1" comment="libpurple-devel is earlier than 0:2.6.2-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:38811"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140803" version="1" comment="cyrus-imapd-murder is earlier than 0:2.2.12-10.el4_8.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14681"/>
      <state state_ref="oval:org.mitre.oval:ste:39343"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140796" version="1" comment="cyrus-imapd-perl is earlier than 0:2.3.7-7.el5_4.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14774"/>
      <state state_ref="oval:org.mitre.oval:ste:38979"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140716" version="1" comment="cyrus-imapd-nntp is earlier than 0:2.2.12-10.el4_8.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14271"/>
      <state state_ref="oval:org.mitre.oval:ste:39343"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140678" version="1" comment="cyrus-imapd-devel is earlier than 0:2.2.12-10.el4_8.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3584"/>
      <state state_ref="oval:org.mitre.oval:ste:39343"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140575" version="1" comment="cyrus-imapd-utils is earlier than 0:2.2.12-10.el4_8.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14555"/>
      <state state_ref="oval:org.mitre.oval:ste:39343"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140569" version="1" comment="cyrus-imapd-devel is earlier than 0:2.3.7-7.el5_4.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3584"/>
      <state state_ref="oval:org.mitre.oval:ste:38979"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140530" version="1" comment="cyrus-imapd is earlier than 0:2.2.12-10.el4_8.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3854"/>
      <state state_ref="oval:org.mitre.oval:ste:39343"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140496" version="1" comment="cyrus-imapd is earlier than 0:2.3.7-7.el5_4.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3854"/>
      <state state_ref="oval:org.mitre.oval:ste:38979"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140401" version="1" comment="cyrus-imapd-utils is earlier than 0:2.3.7-7.el5_4.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14555"/>
      <state state_ref="oval:org.mitre.oval:ste:38979"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140077" version="1" comment="perl-Cyrus is earlier than 0:2.2.12-10.el4_8.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14532"/>
      <state state_ref="oval:org.mitre.oval:ste:39343"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140853" version="1" comment="openssl-devel is earlier than 0:0.9.8e-12.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:39435"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140632" version="1" comment="openssl-perl is earlier than 0:0.9.8e-12.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:39435"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140488" version="1" comment="openssl is earlier than 0:0.9.8e-12.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:39435"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140474" version="1" comment="evolution28-evolution-data-server-devel is earlier than 0:1.8.0-37.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14267"/>
      <state state_ref="oval:org.mitre.oval:ste:38876"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140413" version="1" comment="evolution28-evolution-data-server is earlier than 0:1.8.0-37.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15151"/>
      <state state_ref="oval:org.mitre.oval:ste:38876"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140255" version="1" comment="evolution-data-server-devel is earlier than 0:1.12.3-10.el5_3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14847"/>
      <state state_ref="oval:org.mitre.oval:ste:39313"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140218" version="1" comment="evolution-data-server-doc is earlier than 0:1.12.3-10.el5_3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15054"/>
      <state state_ref="oval:org.mitre.oval:ste:39313"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139962" version="1" comment="evolution-data-server is earlier than 0:1.12.3-10.el5_3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14939"/>
      <state state_ref="oval:org.mitre.oval:ste:39313"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140291" version="1" comment="firefox is earlier than 0:3.0.10-1.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39246"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140280" version="1" comment="firefox is earlier than 0:3.0.10-1.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:38973"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140199" version="1" comment="firefox is earlier than 0:3.0.10-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:39115"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140196" version="1" comment="xulrunner is earlier than 0:1.9.0.10-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:38404"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140160" version="1" comment="xulrunner-devel is earlier than 0:1.9.0.10-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:38404"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139657" version="1" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.10-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15048"/>
      <state state_ref="oval:org.mitre.oval:ste:38404"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139795" version="1" comment="thunderbird is earlier than 0:2.0.0.16-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:39201"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139651" version="1" comment="thunderbird is earlier than 0:1.5.0.12-14.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:38940"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140549" version="1" comment="openssl096b is earlier than 0:0.9.6b-22.46.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14258"/>
      <state state_ref="oval:org.mitre.oval:ste:39280"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140514" version="1" comment="openssl-devel is earlier than 0:0.9.7a-43.17.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:38689"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140500" version="1" comment="openssl is earlier than 0:0.9.7a-43.17.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:38689"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140483" version="1" comment="openssl-perl is earlier than 0:0.9.7a-33.25" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:38975"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140419" version="1" comment="openssl-perl is earlier than 0:0.9.8b-10.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:39061"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140394" version="1" comment="openssl is earlier than 0:0.9.7a-33.25" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:38975"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140346" version="1" comment="openssl096b is earlier than 0:0.9.6b-16.49" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14258"/>
      <state state_ref="oval:org.mitre.oval:ste:39156"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140341" version="1" comment="openssl is earlier than 0:0.9.8b-10.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:39061"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140259" version="1" comment="openssl-devel is earlier than 0:0.9.8b-10.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:39061"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140254" version="1" comment="openssl-perl is earlier than 0:0.9.7a-43.17.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:38689"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140156" version="1" comment="openssl-devel is earlier than 0:0.9.7a-33.25" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:38975"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139591" version="1" comment="openssl097a is earlier than 0:0.9.7a-9.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14181"/>
      <state state_ref="oval:org.mitre.oval:ste:39365"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140250" version="1" comment="libvolume_id-devel is earlier than 0:095-14.20.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15260"/>
      <state state_ref="oval:org.mitre.oval:ste:39147"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139965" version="1" comment="libvolume_id is earlier than 0:095-14.20.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14494"/>
      <state state_ref="oval:org.mitre.oval:ste:39147"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139917" version="1" comment="udev is earlier than 0:095-14.20.el5_3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14607"/>
      <state state_ref="oval:org.mitre.oval:ste:39147"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139881" version="1" comment="thunderbird is earlier than 0:1.5.0.12-16.el4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:38987"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139840" version="1" comment="thunderbird is earlier than 0:2.0.0.17-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:39086"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139384" version="1" comment="thunderbird is earlier than 0:2.0.0.17-1.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:39017"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140680" version="1" comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14273"/>
      <state state_ref="oval:org.mitre.oval:ste:39382"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140669" version="1" comment="ruby-libs is earlier than 0:1.8.1-7.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14388"/>
      <state state_ref="oval:org.mitre.oval:ste:39382"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140614" version="1" comment="ruby-devel is earlier than 0:1.8.1-7.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14187"/>
      <state state_ref="oval:org.mitre.oval:ste:39382"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140613" version="1" comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14388"/>
      <state state_ref="oval:org.mitre.oval:ste:39216"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140562" version="1" comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14446"/>
      <state state_ref="oval:org.mitre.oval:ste:39216"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140555" version="1" comment="ruby is earlier than 0:1.8.5-5.el5_2.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14305"/>
      <state state_ref="oval:org.mitre.oval:ste:39216"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140548" version="1" comment="ruby is earlier than 0:1.8.1-7.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14305"/>
      <state state_ref="oval:org.mitre.oval:ste:39382"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140543" version="1" comment="ruby-mode is earlier than 0:1.8.1-7.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14380"/>
      <state state_ref="oval:org.mitre.oval:ste:39382"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140384" version="1" comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14461"/>
      <state state_ref="oval:org.mitre.oval:ste:39216"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140360" version="1" comment="irb is earlier than 0:1.8.1-7.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13649"/>
      <state state_ref="oval:org.mitre.oval:ste:39382"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140310" version="1" comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14777"/>
      <state state_ref="oval:org.mitre.oval:ste:39216"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140276" version="1" comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14273"/>
      <state state_ref="oval:org.mitre.oval:ste:39216"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140116" version="1" comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14187"/>
      <state state_ref="oval:org.mitre.oval:ste:39216"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140100" version="1" comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14244"/>
      <state state_ref="oval:org.mitre.oval:ste:39216"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139730" version="1" comment="ruby-docs is earlier than 0:1.8.1-7.el4_7.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14446"/>
      <state state_ref="oval:org.mitre.oval:ste:39382"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139699" version="1" comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14380"/>
      <state state_ref="oval:org.mitre.oval:ste:39216"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137248" version="1" comment="rpm-devel is earlier than 0:4.8.0-38.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29870"/>
      <state state_ref="oval:org.mitre.oval:ste:37720"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137235" version="1" comment="rpm-python is earlier than 0:4.4.2.3-36.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30203"/>
      <state state_ref="oval:org.mitre.oval:ste:37167"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137213" version="1" comment="rpm-python is earlier than 0:4.8.0-38.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30203"/>
      <state state_ref="oval:org.mitre.oval:ste:37720"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137203" version="1" comment="rpm-debuginfo is earlier than 0:4.8.0-38.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43266"/>
      <state state_ref="oval:org.mitre.oval:ste:37720"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137172" version="1" comment="rpm-debuginfo is earlier than 0:4.4.2.3-36.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43266"/>
      <state state_ref="oval:org.mitre.oval:ste:37167"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137165" version="1" comment="rpm is earlier than 0:4.4.2.3-36.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29900"/>
      <state state_ref="oval:org.mitre.oval:ste:37167"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137066" version="1" comment="rpm-build is earlier than 0:4.8.0-38.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30336"/>
      <state state_ref="oval:org.mitre.oval:ste:37720"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137062" version="1" comment="rpm-devel is earlier than 0:4.4.2.3-36.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29870"/>
      <state state_ref="oval:org.mitre.oval:ste:37167"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137047" version="1" comment="rpm-cron is earlier than 0:4.8.0-38.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29996"/>
      <state state_ref="oval:org.mitre.oval:ste:37720"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137024" version="1" comment="rpm is earlier than 0:4.8.0-38.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29900"/>
      <state state_ref="oval:org.mitre.oval:ste:37720"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136922" version="1" comment="rpm-apidocs is earlier than 0:4.4.2.3-36.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30029"/>
      <state state_ref="oval:org.mitre.oval:ste:37167"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136878" version="1" comment="rpm-libs is earlier than 0:4.4.2.3-36.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30299"/>
      <state state_ref="oval:org.mitre.oval:ste:37167"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136811" version="1" comment="rpm-apidocs is earlier than 0:4.8.0-38.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30029"/>
      <state state_ref="oval:org.mitre.oval:ste:37720"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136793" version="1" comment="popt is earlier than 0:1.10.2.3-36.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29846"/>
      <state state_ref="oval:org.mitre.oval:ste:37311"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136765" version="1" comment="rpm-libs is earlier than 0:4.8.0-38.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30299"/>
      <state state_ref="oval:org.mitre.oval:ste:37720"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136747" version="1" comment="rpm-build is earlier than 0:4.4.2.3-36.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30336"/>
      <state state_ref="oval:org.mitre.oval:ste:37167"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137238" version="1" comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.107.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14709"/>
      <state state_ref="oval:org.mitre.oval:ste:37914"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137219" version="1" comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.107.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14667"/>
      <state state_ref="oval:org.mitre.oval:ste:37914"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137218" version="1" comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.107.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14667"/>
      <state state_ref="oval:org.mitre.oval:ste:37982"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137184" version="1" comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.107.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14873"/>
      <state state_ref="oval:org.mitre.oval:ste:37914"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137142" version="1" comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.107.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14353"/>
      <state state_ref="oval:org.mitre.oval:ste:37914"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137140" version="1" comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.107.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14653"/>
      <state state_ref="oval:org.mitre.oval:ste:37982"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137131" version="1" comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.107.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14353"/>
      <state state_ref="oval:org.mitre.oval:ste:37982"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137110" version="1" comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.107.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14842"/>
      <state state_ref="oval:org.mitre.oval:ste:37914"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136986" version="1" comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.107.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14794"/>
      <state state_ref="oval:org.mitre.oval:ste:37914"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136985" version="1" comment="xorg-x11-server-debuginfo is earlier than 0:1.1.1-48.107.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42697"/>
      <state state_ref="oval:org.mitre.oval:ste:37982"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136937" version="1" comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.107.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14842"/>
      <state state_ref="oval:org.mitre.oval:ste:37982"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136903" version="1" comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.107.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14794"/>
      <state state_ref="oval:org.mitre.oval:ste:37982"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136872" version="1" comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.107.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14709"/>
      <state state_ref="oval:org.mitre.oval:ste:37982"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136828" version="1" comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.107.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14653"/>
      <state state_ref="oval:org.mitre.oval:ste:37914"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136732" version="1" comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.107.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14873"/>
      <state state_ref="oval:org.mitre.oval:ste:37982"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140976" version="1" comment="bind-libs is earlier than 30:9.3.4-10.P1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:38536"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140950" version="1" comment="bind-libbind-devel is earlier than 30:9.3.4-10.P1.el5_3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14729"/>
      <state state_ref="oval:org.mitre.oval:ste:39180"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140860" version="1" comment="bind-sdb is earlier than 30:9.3.4-10.P1.el5_3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:39180"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140832" version="1" comment="bind-libbind-devel is earlier than 30:9.3.4-10.P1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14729"/>
      <state state_ref="oval:org.mitre.oval:ste:38536"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140830" version="1" comment="caching-nameserver is earlier than 30:9.3.4-10.P1.el5_3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14701"/>
      <state state_ref="oval:org.mitre.oval:ste:39180"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140827" version="1" comment="bind-chroot is earlier than 30:9.3.4-10.P1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:38536"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140820" version="1" comment="bind is earlier than 30:9.3.4-10.P1.el5_3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:39180"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140714" version="1" comment="bind-devel is earlier than 30:9.3.4-10.P1.el5_3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:39180"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140656" version="1" comment="bind-utils is earlier than 30:9.3.4-10.P1.el5_3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:39180"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140631" version="1" comment="bind is earlier than 30:9.3.4-10.P1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:38536"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140566" version="1" comment="bind-chroot is earlier than 30:9.3.4-10.P1.el5_3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:39180"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140561" version="1" comment="bind-devel is earlier than 30:9.3.4-10.P1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:38536"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140535" version="1" comment="bind-sdb is earlier than 30:9.3.4-10.P1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:38536"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140469" version="1" comment="bind-libs is earlier than 30:9.3.4-10.P1.el5_3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:39180"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140316" version="1" comment="bind-utils is earlier than 30:9.3.4-10.P1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:38536"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140293" version="1" comment="caching-nameserver is earlier than 30:9.3.4-10.P1.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14701"/>
      <state state_ref="oval:org.mitre.oval:ste:38536"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140910" version="1" comment="kernel-xen is earlier than 0:2.6.18-128.7.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:38990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140907" version="1" comment="kernel-PAE is earlier than 0:2.6.18-128.7.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:38990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140877" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.7.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:38990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140778" version="1" comment="kernel is earlier than 0:2.6.18-128.7.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:38990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140777" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-128.7.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:38990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140767" version="1" comment="kernel-headers is earlier than 0:2.6.18-128.7.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:38990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140695" version="1" comment="kernel-debug is earlier than 0:2.6.18-128.7.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:38990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140623" version="1" comment="kernel-devel is earlier than 0:2.6.18-128.7.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:38990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140503" version="1" comment="kernel-doc is earlier than 0:2.6.18-128.7.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:38990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140406" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-128.7.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:38990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141083" version="1" comment="kernel-xen is earlier than 0:2.6.18-128.1.14.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:38883"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141049" version="1" comment="kernel-debug is earlier than 0:2.6.18-128.1.14.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:38883"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141016" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.14.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:38883"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140847" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.14.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:38883"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140840" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.14.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:38883"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140839" version="1" comment="kernel-devel is earlier than 0:2.6.18-128.1.14.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:38883"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140838" version="1" comment="kernel-headers is earlier than 0:2.6.18-128.1.14.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:38883"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140807" version="1" comment="kernel-PAE is earlier than 0:2.6.18-128.1.14.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:38883"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140721" version="1" comment="kernel-doc is earlier than 0:2.6.18-128.1.14.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:38883"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140621" version="1" comment="kernel is earlier than 0:2.6.18-128.1.14.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:38883"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140309" version="1" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14076"/>
      <state state_ref="oval:org.mitre.oval:ste:39312"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140308" version="1" comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14199"/>
      <state state_ref="oval:org.mitre.oval:ste:39312"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140287" version="1" comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14688"/>
      <state state_ref="oval:org.mitre.oval:ste:39386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140168" version="1" comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14076"/>
      <state state_ref="oval:org.mitre.oval:ste:39386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140167" version="1" comment="cups is earlier than 1:1.3.7-8.el5_3.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14199"/>
      <state state_ref="oval:org.mitre.oval:ste:39386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139867" version="1" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14195"/>
      <state state_ref="oval:org.mitre.oval:ste:39312"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139317" version="1" comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14195"/>
      <state state_ref="oval:org.mitre.oval:ste:39386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137244" version="2" comment="bind-devel is earlier than 32:9.8.2-0.30.rc1.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:37698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137206" version="2" comment="bind-sdb is earlier than 32:9.8.2-0.30.rc1.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:37698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137177" version="2" comment="bind-debuginfo is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42594"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137151" version="2" comment="bind-libs is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137146" version="2" comment="bind-utils is earlier than 32:9.8.2-0.30.rc1.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:37698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137141" version="2" comment="bind-debuginfo is earlier than 30:9.3.6-25.P1.el5_11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42594"/>
      <state state_ref="oval:org.mitre.oval:ste:38033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137117" version="2" comment="bind-debuginfo is earlier than 32:9.8.2-0.30.rc1.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42594"/>
      <state state_ref="oval:org.mitre.oval:ste:37698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137092" version="2" comment="bind-libs is earlier than 32:9.8.2-0.30.rc1.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:37698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137085" version="2" comment="bind-utils is earlier than 30:9.3.6-25.P1.el5_11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:38033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137052" version="2" comment="bind-sdb is earlier than 30:9.3.6-25.P1.el5_11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:38033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137048" version="2" comment="bind-sdb-chroot is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43276"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137046" version="2" comment="bind is earlier than 30:9.3.6-25.P1.el5_11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:38033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137044" version="2" comment="bind-libs-lite is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42827"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137022" version="2" comment="bind-libbind-devel is earlier than 30:9.3.6-25.P1.el5_11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14729"/>
      <state state_ref="oval:org.mitre.oval:ste:38033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137013" version="2" comment="bind-devel is earlier than 30:9.3.6-25.P1.el5_11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:38033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137006" version="2" comment="bind-chroot is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136991" version="2" comment="bind-chroot is earlier than 30:9.3.6-25.P1.el5_11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:38033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136944" version="2" comment="bind is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136926" version="2" comment="bind-sdb is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136871" version="2" comment="bind-license is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43057"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136841" version="2" comment="bind-libs is earlier than 30:9.3.6-25.P1.el5_11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:38033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136778" version="2" comment="bind-utils is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136695" version="2" comment="bind-lite-devel is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43139"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136550" version="2" comment="bind is earlier than 32:9.8.2-0.30.rc1.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:37698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136436" version="2" comment="bind-devel is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136320" version="2" comment="caching-nameserver is earlier than 30:9.3.6-25.P1.el5_11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14701"/>
      <state state_ref="oval:org.mitre.oval:ste:38033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136248" version="2" comment="bind-chroot is earlier than 32:9.8.2-0.30.rc1.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:37698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138720" version="1" comment="xen is earlier than 0:3.0.3-146.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30216"/>
      <state state_ref="oval:org.mitre.oval:ste:38284"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138433" version="1" comment="xen-debuginfo is earlier than 0:3.0.3-146.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:44042"/>
      <state state_ref="oval:org.mitre.oval:ste:38284"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138283" version="1" comment="xen-libs is earlier than 0:3.0.3-146.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30487"/>
      <state state_ref="oval:org.mitre.oval:ste:38284"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140210" version="1" comment="openssl is earlier than 0:0.9.8e-33.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:39178"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140187" version="1" comment="openssl-devel is earlier than 0:0.9.8e-33.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:39178"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140051" version="1" comment="openssl-debuginfo is earlier than 0:0.9.8e-33.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43044"/>
      <state state_ref="oval:org.mitre.oval:ste:39178"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139632" version="1" comment="openssl-perl is earlier than 0:0.9.8e-33.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:39178"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137100" version="2" comment="bind97-libs is earlier than 32:9.7.0-21.P2.el5_11.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29535"/>
      <state state_ref="oval:org.mitre.oval:ste:38054"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137080" version="2" comment="bind97 is earlier than 32:9.7.0-21.P2.el5_11.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28886"/>
      <state state_ref="oval:org.mitre.oval:ste:38054"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137018" version="2" comment="bind97-devel is earlier than 32:9.7.0-21.P2.el5_11.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29237"/>
      <state state_ref="oval:org.mitre.oval:ste:38054"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136973" version="2" comment="bind97-chroot is earlier than 32:9.7.0-21.P2.el5_11.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29448"/>
      <state state_ref="oval:org.mitre.oval:ste:38054"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136919" version="2" comment="bind97-debuginfo is earlier than 32:9.7.0-21.P2.el5_11.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42672"/>
      <state state_ref="oval:org.mitre.oval:ste:38054"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136784" version="2" comment="bind97-utils is earlier than 32:9.7.0-21.P2.el5_11.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28577"/>
      <state state_ref="oval:org.mitre.oval:ste:38054"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141060" version="1" comment="ipsec-tools is earlier than 0:0.6.5-13.el5_3.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14216"/>
      <state state_ref="oval:org.mitre.oval:ste:39209"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137069" version="2" comment="ntp-debuginfo is earlier than 0:4.2.2p1-18.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42942"/>
      <state state_ref="oval:org.mitre.oval:ste:37784"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136750" version="1" comment="ntp is earlier than 0:4.2.2p1-18.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14371"/>
      <state state_ref="oval:org.mitre.oval:ste:38058"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136694" version="2" comment="ntp is earlier than 0:4.2.2p1-18.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14371"/>
      <state state_ref="oval:org.mitre.oval:ste:37784"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136206" version="1" comment="thunderbird is earlier than 0:31.3.0-1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:37600"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136134" version="1" comment="thunderbird is earlier than 0:31.3.0-1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:37692"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136131" version="1" comment="thunderbird-debuginfo is earlier than 0:31.3.0-1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43263"/>
      <state state_ref="oval:org.mitre.oval:ste:37600"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135999" version="1" comment="thunderbird is earlier than 0:31.3.0-1.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:37781"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135692" version="1" comment="thunderbird-debuginfo is earlier than 0:31.3.0-1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43263"/>
      <state state_ref="oval:org.mitre.oval:ste:37692"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135513" version="1" comment="thunderbird is earlier than 0:31.3.0-1.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:37863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137152" version="1" comment="kernel-debuginfo-common is earlier than 0:2.6.18-400.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14853"/>
      <state state_ref="oval:org.mitre.oval:ste:38060"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137090" version="1" comment="kernel-xen-debuginfo is earlier than 0:2.6.18-400.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42411"/>
      <state state_ref="oval:org.mitre.oval:ste:38060"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137063" version="1" comment="kernel-debug-debuginfo is earlier than 0:2.6.18-400.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42590"/>
      <state state_ref="oval:org.mitre.oval:ste:38060"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137053" version="1" comment="kernel is earlier than 0:2.6.18-400.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:38060"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137003" version="1" comment="kernel-debuginfo is earlier than 0:2.6.18-400.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42117"/>
      <state state_ref="oval:org.mitre.oval:ste:38060"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137001" version="1" comment="kernel-devel is earlier than 0:2.6.18-400.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:38060"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136994" version="1" comment="kernel-debug is earlier than 0:2.6.18-400.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:38060"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136867" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-400.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:38060"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136736" version="1" comment="kernel-headers is earlier than 0:2.6.18-400.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:38060"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136511" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-400.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:38060"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136459" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-400.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:38060"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136391" version="1" comment="kernel-doc is earlier than 0:2.6.18-400.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:38060"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136351" version="1" comment="kernel-PAE is earlier than 0:2.6.18-400.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:38060"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136182" version="1" comment="kernel-PAE-debuginfo is earlier than 0:2.6.18-400.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42166"/>
      <state state_ref="oval:org.mitre.oval:ste:38060"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136155" version="1" comment="kernel-xen is earlier than 0:2.6.18-400.1.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:38060"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140251" version="1" comment="krb5-devel is earlier than 0:1.6.1-31.el5_3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14100"/>
      <state state_ref="oval:org.mitre.oval:ste:38794"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140217" version="1" comment="krb5-workstation is earlier than 0:1.6.1-31.el5_3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14279"/>
      <state state_ref="oval:org.mitre.oval:ste:38794"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140208" version="1" comment="krb5-libs is earlier than 0:1.6.1-31.el5_3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14395"/>
      <state state_ref="oval:org.mitre.oval:ste:38794"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139823" version="1" comment="krb5-server is earlier than 0:1.6.1-31.el5_3.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14452"/>
      <state state_ref="oval:org.mitre.oval:ste:38794"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139253" version="1" comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.7.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14662"/>
      <state state_ref="oval:org.mitre.oval:ste:38800"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139244" version="1" comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.7.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14622"/>
      <state state_ref="oval:org.mitre.oval:ste:38800"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139198" version="1" comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.7.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14685"/>
      <state state_ref="oval:org.mitre.oval:ste:38800"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139167" version="1" comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.7.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14686"/>
      <state state_ref="oval:org.mitre.oval:ste:38800"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139134" version="1" comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.7.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14750"/>
      <state state_ref="oval:org.mitre.oval:ste:38800"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139061" version="1" comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.7.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14808"/>
      <state state_ref="oval:org.mitre.oval:ste:38800"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139032" version="1" comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.7.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14815"/>
      <state state_ref="oval:org.mitre.oval:ste:38800"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138959" version="1" comment="tomcat5 is earlier than 0:5.5.23-0jpp.7.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14612"/>
      <state state_ref="oval:org.mitre.oval:ste:38800"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138953" version="1" comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.7.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14210"/>
      <state state_ref="oval:org.mitre.oval:ste:38800"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138719" version="1" comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.7.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14509"/>
      <state state_ref="oval:org.mitre.oval:ste:38800"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138326" version="1" comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.7.el5_2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14332"/>
      <state state_ref="oval:org.mitre.oval:ste:38800"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141033" version="1" comment="mod_ssl is earlier than 0:2.2.3-22.el5.centos.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:39495"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140936" version="1" comment="httpd-devel is earlier than 0:2.2.3-22.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14256"/>
      <state state_ref="oval:org.mitre.oval:ste:39324"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140927" version="1" comment="mod_ssl is earlier than 0:2.2.3-22.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:39324"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140763" version="1" comment="httpd-devel is earlier than 0:2.2.3-22.el5.centos.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14256"/>
      <state state_ref="oval:org.mitre.oval:ste:39495"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140580" version="1" comment="httpd is earlier than 0:2.2.3-22.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:39324"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140545" version="1" comment="httpd-manual is earlier than 0:2.2.3-22.el5.centos.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:39495"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140525" version="1" comment="httpd is earlier than 0:2.2.3-22.el5.centos.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:39495"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140350" version="1" comment="httpd-manual is earlier than 0:2.2.3-22.el5_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:39324"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136168" version="1" comment="mysql55-mysql-devel is earlier than 0:5.5.40-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:35113"/>
      <state state_ref="oval:org.mitre.oval:ste:37618"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136137" version="1" comment="mysql55-mysql-test is earlier than 0:5.5.40-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:35130"/>
      <state state_ref="oval:org.mitre.oval:ste:37618"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136114" version="1" comment="mysql55-mysql-libs is earlier than 0:5.5.40-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:34878"/>
      <state state_ref="oval:org.mitre.oval:ste:37618"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136053" version="1" comment="mysql55-mysql-server is earlier than 0:5.5.40-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:34983"/>
      <state state_ref="oval:org.mitre.oval:ste:37618"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135921" version="1" comment="mysql55-mysql-debuginfo is earlier than 0:5.5.40-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42509"/>
      <state state_ref="oval:org.mitre.oval:ste:37618"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135750" version="1" comment="mysql55-mysql is earlier than 0:5.5.40-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:35044"/>
      <state state_ref="oval:org.mitre.oval:ste:37618"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135584" version="1" comment="mysql55-mysql-bench is earlier than 0:5.5.40-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:34724"/>
      <state state_ref="oval:org.mitre.oval:ste:37618"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137721" version="1" comment="glibc-utils is earlier than 0:2.5-123.el5_11.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14059"/>
      <state state_ref="oval:org.mitre.oval:ste:37757"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137702" version="1" comment="glibc-devel is earlier than 0:2.5-123.el5_11.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14346"/>
      <state state_ref="oval:org.mitre.oval:ste:37757"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137694" version="1" comment="glibc-debuginfo-common is earlier than 0:2.5-123.el5_11.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42178"/>
      <state state_ref="oval:org.mitre.oval:ste:37757"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137647" version="1" comment="glibc is earlier than 0:2.5-123.el5_11.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14142"/>
      <state state_ref="oval:org.mitre.oval:ste:37757"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137627" version="1" comment="glibc-headers is earlier than 0:2.5-123.el5_11.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13936"/>
      <state state_ref="oval:org.mitre.oval:ste:37757"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137625" version="1" comment="glibc-common is earlier than 0:2.5-123.el5_11.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14374"/>
      <state state_ref="oval:org.mitre.oval:ste:37757"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137572" version="1" comment="nscd is earlier than 0:2.5-123.el5_11.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14360"/>
      <state state_ref="oval:org.mitre.oval:ste:37757"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137530" version="1" comment="glibc-debuginfo is earlier than 0:2.5-123.el5_11.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4398"/>
      <state state_ref="oval:org.mitre.oval:ste:37757"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136303" version="1" comment="php53-intl is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29195"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136299" version="1" comment="php53-pdo is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29253"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136292" version="1" comment="php53-debuginfo is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42663"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136285" version="1" comment="php53-soap is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29455"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136277" version="1" comment="php53-odbc is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29337"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136244" version="1" comment="php53-devel is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29547"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136230" version="1" comment="php53-xmlrpc is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29475"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136192" version="1" comment="php53 is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29556"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136160" version="1" comment="php53-dba is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28950"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136143" version="1" comment="php53-ldap is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29602"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136138" version="1" comment="php53-gd is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29626"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136136" version="1" comment="php53-pspell is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29208"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136132" version="1" comment="php53-xml is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29235"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136125" version="1" comment="php53-snmp is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29427"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136121" version="1" comment="php53-mbstring is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29008"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136117" version="1" comment="php53-cli is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28902"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136089" version="1" comment="php53-mysql is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29022"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136067" version="1" comment="php53-bcmath is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29087"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136008" version="1" comment="php53-imap is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29568"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135938" version="1" comment="php53-common is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29562"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135870" version="1" comment="php53-process is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29375"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135553" version="1" comment="php53-pgsql is earlier than 0:5.3.3-26.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29505"/>
      <state state_ref="oval:org.mitre.oval:ste:37360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136038" version="1" comment="kernel is earlier than 0:2.6.18-400.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:37804"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136027" version="1" comment="kernel-debug-debuginfo is earlier than 0:2.6.18-400.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42590"/>
      <state state_ref="oval:org.mitre.oval:ste:37804"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136019" version="1" comment="kernel-devel is earlier than 0:2.6.18-400.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:37804"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136000" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-400.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:37804"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135987" version="1" comment="kernel-PAE is earlier than 0:2.6.18-400.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:37804"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135986" version="1" comment="kernel-doc is earlier than 0:2.6.18-400.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:37804"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135967" version="1" comment="kernel-debuginfo is earlier than 0:2.6.18-400.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42117"/>
      <state state_ref="oval:org.mitre.oval:ste:37804"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135933" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-400.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:37804"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135853" version="1" comment="kernel-PAE-debuginfo is earlier than 0:2.6.18-400.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42166"/>
      <state state_ref="oval:org.mitre.oval:ste:37804"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135677" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-400.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:37804"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135642" version="1" comment="kernel-debuginfo-common is earlier than 0:2.6.18-400.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14853"/>
      <state state_ref="oval:org.mitre.oval:ste:37804"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135585" version="1" comment="kernel-xen is earlier than 0:2.6.18-400.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:37804"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135295" version="1" comment="kernel-xen-debuginfo is earlier than 0:2.6.18-400.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42411"/>
      <state state_ref="oval:org.mitre.oval:ste:37804"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135097" version="1" comment="kernel-debug is earlier than 0:2.6.18-400.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:37804"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135065" version="1" comment="kernel-headers is earlier than 0:2.6.18-400.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:37804"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:7836" version="3" comment="Red Hat Enterprise 3 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1414"/>
      <state state_ref="oval:org.mitre.oval:ste:11298"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139225" version="1" comment="postfix-pflogsumm is earlier than 2:2.3.3-2.1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14593"/>
      <state state_ref="oval:org.mitre.oval:ste:38818"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139219" version="1" comment="postfix is earlier than 2:2.0.16-14.1.RHEL3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1466"/>
      <state state_ref="oval:org.mitre.oval:ste:38759"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138999" version="1" comment="postfix is earlier than 2:2.2.10-1.2.1.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1466"/>
      <state state_ref="oval:org.mitre.oval:ste:38885"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138922" version="1" comment="postfix-pflogsumm is earlier than 2:2.2.10-1.2.1.el4_7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14593"/>
      <state state_ref="oval:org.mitre.oval:ste:38885"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138734" version="1" comment="postfix is earlier than 2:2.3.3-2.1.el5_2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1466"/>
      <state state_ref="oval:org.mitre.oval:ste:38818"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2652" version="3" comment="Red Hat Enterprise 4 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1414"/>
      <state state_ref="oval:org.mitre.oval:ste:11366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139115" version="1" comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14777"/>
      <state state_ref="oval:org.mitre.oval:ste:39112"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139098" version="1" comment="ruby-libs is earlier than 0:1.8.1-7.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14388"/>
      <state state_ref="oval:org.mitre.oval:ste:38719"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139094" version="1" comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14380"/>
      <state state_ref="oval:org.mitre.oval:ste:39112"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139089" version="1" comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14461"/>
      <state state_ref="oval:org.mitre.oval:ste:39112"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138998" version="1" comment="ruby-docs is earlier than 0:1.8.1-7.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14446"/>
      <state state_ref="oval:org.mitre.oval:ste:38719"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138996" version="1" comment="ruby is earlier than 0:1.8.1-7.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14305"/>
      <state state_ref="oval:org.mitre.oval:ste:38719"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138944" version="1" comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14187"/>
      <state state_ref="oval:org.mitre.oval:ste:39112"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138924" version="1" comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14273"/>
      <state state_ref="oval:org.mitre.oval:ste:38719"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138920" version="1" comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14244"/>
      <state state_ref="oval:org.mitre.oval:ste:39112"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138895" version="1" comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14273"/>
      <state state_ref="oval:org.mitre.oval:ste:39112"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138888" version="1" comment="ruby-devel is earlier than 0:1.8.1-7.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14187"/>
      <state state_ref="oval:org.mitre.oval:ste:38719"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138873" version="1" comment="irb is earlier than 0:1.8.1-7.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13649"/>
      <state state_ref="oval:org.mitre.oval:ste:38719"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138826" version="1" comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14388"/>
      <state state_ref="oval:org.mitre.oval:ste:39112"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138743" version="1" comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14446"/>
      <state state_ref="oval:org.mitre.oval:ste:39112"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138539" version="1" comment="ruby is earlier than 0:1.8.5-5.el5_2.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14305"/>
      <state state_ref="oval:org.mitre.oval:ste:39112"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138414" version="1" comment="ruby-mode is earlier than 0:1.8.1-7.el4_7.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14380"/>
      <state state_ref="oval:org.mitre.oval:ste:38719"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136200" version="1" comment="php-common is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14841"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136197" version="1" comment="php-xml is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14560"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136179" version="1" comment="php-pgsql is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14148"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136162" version="1" comment="php-odbc is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14183"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136150" version="1" comment="php-devel is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13492"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136140" version="1" comment="php-dba is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14512"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136076" version="1" comment="php-mysql is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14080"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136056" version="1" comment="php-xmlrpc is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14445"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136016" version="1" comment="php-ncurses is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14227"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136015" version="1" comment="php-soap is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14366"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136014" version="1" comment="php-snmp is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14508"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135968" version="1" comment="php-pdo is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14154"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135956" version="1" comment="php-bcmath is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14639"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135806" version="1" comment="php-imap is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14250"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135782" version="1" comment="php-cli is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14922"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135711" version="1" comment="php is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14294"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135670" version="1" comment="php-mbstring is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13746"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135391" version="1" comment="php-debuginfo is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42299"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135302" version="1" comment="php-ldap is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14375"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135238" version="1" comment="php-gd is earlier than 0:5.1.6-45.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14335"/>
      <state state_ref="oval:org.mitre.oval:ste:36977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136207" version="1" comment="nss-util-debuginfo is earlier than 0:3.16.2.3-1.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42869"/>
      <state state_ref="oval:org.mitre.oval:ste:37666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136106" version="1" comment="nss-util-debuginfo is earlier than 0:3.16.2.3-2.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42869"/>
      <state state_ref="oval:org.mitre.oval:ste:37481"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136093" version="1" comment="nss-softokn-devel is earlier than 0:3.16.2.3-1.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29485"/>
      <state state_ref="oval:org.mitre.oval:ste:37666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136085" version="1" comment="nss-softokn-debuginfo is earlier than 0:3.16.2.3-1.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43053"/>
      <state state_ref="oval:org.mitre.oval:ste:37666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136083" version="1" comment="nss-tools is earlier than 0:3.16.2.3-2.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:37825"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136072" version="1" comment="nss-sysinit is earlier than 0:3.16.2.3-2.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28504"/>
      <state state_ref="oval:org.mitre.oval:ste:37825"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136065" version="1" comment="nss-util-devel is earlier than 0:3.16.2.3-1.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29207"/>
      <state state_ref="oval:org.mitre.oval:ste:37666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136054" version="1" comment="nss-pkcs11-devel is earlier than 0:3.16.2.3-1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:37644"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136049" version="1" comment="nss-util is earlier than 0:3.16.2.3-1.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29019"/>
      <state state_ref="oval:org.mitre.oval:ste:37666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136028" version="1" comment="nss-debuginfo is earlier than 0:3.16.2.3-1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42328"/>
      <state state_ref="oval:org.mitre.oval:ste:37644"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135977" version="1" comment="nss is earlier than 0:3.16.2.3-1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:37644"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135957" version="1" comment="nss-pkcs11-devel is earlier than 0:3.16.2.3-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:37821"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135941" version="1" comment="nss-softokn is earlier than 0:3.16.2.3-1.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29421"/>
      <state state_ref="oval:org.mitre.oval:ste:37666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135936" version="1" comment="nss-debuginfo is earlier than 0:3.16.2.3-2.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42328"/>
      <state state_ref="oval:org.mitre.oval:ste:37825"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135877" version="1" comment="nss-util-devel is earlier than 0:3.16.2.3-2.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29207"/>
      <state state_ref="oval:org.mitre.oval:ste:37481"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135854" version="1" comment="nss-tools is earlier than 0:3.16.2.3-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:37821"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135848" version="1" comment="nss-devel is earlier than 0:3.16.2.3-1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:37644"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135797" version="1" comment="nss-softokn-freebl is earlier than 0:3.16.2.3-1.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29159"/>
      <state state_ref="oval:org.mitre.oval:ste:37666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135785" version="1" comment="nss is earlier than 0:3.16.2.3-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:37821"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135718" version="1" comment="nss-devel is earlier than 0:3.16.2.3-2.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:37825"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135709" version="1" comment="nss-sysinit is earlier than 0:3.16.2.3-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28504"/>
      <state state_ref="oval:org.mitre.oval:ste:37821"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135679" version="1" comment="nss-softokn-freebl-devel is earlier than 0:3.16.2.3-1.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29515"/>
      <state state_ref="oval:org.mitre.oval:ste:37666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135637" version="1" comment="nss-tools is earlier than 0:3.16.2.3-1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:37644"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135612" version="1" comment="nss-devel is earlier than 0:3.16.2.3-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:37821"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135216" version="1" comment="nss-pkcs11-devel is earlier than 0:3.16.2.3-2.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:37825"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135157" version="1" comment="nss is earlier than 0:3.16.2.3-2.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:37825"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135108" version="1" comment="nss-debuginfo is earlier than 0:3.16.2.3-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42328"/>
      <state state_ref="oval:org.mitre.oval:ste:37821"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135104" version="1" comment="nss-util is earlier than 0:3.16.2.3-2.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29019"/>
      <state state_ref="oval:org.mitre.oval:ste:37481"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136031" version="1" comment="firefox is earlier than 0:31.3.0-3.el7.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:37729"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135966" version="1" comment="firefox is earlier than 0:31.3.0-4.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:37610"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135952" version="1" comment="firefox is earlier than 0:31.3.0-3.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:37770"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135920" version="1" comment="firefox-debuginfo is earlier than 0:31.3.0-4.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43227"/>
      <state state_ref="oval:org.mitre.oval:ste:37610"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135768" version="1" comment="firefox-debuginfo is earlier than 0:31.3.0-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43227"/>
      <state state_ref="oval:org.mitre.oval:ste:37777"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135742" version="1" comment="firefox is earlier than 0:31.3.0-4.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:37492"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135687" version="1" comment="firefox is earlier than 0:31.3.0-3.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:37535"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135624" version="1" comment="firefox is earlier than 0:31.3.0-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:37777"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135350" version="1" comment="firefox-debuginfo is earlier than 0:31.3.0-3.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43227"/>
      <state state_ref="oval:org.mitre.oval:ste:37770"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135960" version="1" comment="libXfont-debuginfo is earlier than 0:1.2.2-1.0.6.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43247"/>
      <state state_ref="oval:org.mitre.oval:ste:37734"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135852" version="1" comment="libXfont is earlier than 0:1.2.2-1.0.6.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14504"/>
      <state state_ref="oval:org.mitre.oval:ste:37734"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135703" version="1" comment="libXfont-devel is earlier than 0:1.2.2-1.0.6.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14538"/>
      <state state_ref="oval:org.mitre.oval:ste:37734"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136070" version="1" comment="libxml2-debuginfo is earlier than 0:2.6.26-2.1.25.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42511"/>
      <state state_ref="oval:org.mitre.oval:ste:37853"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136057" version="1" comment="libxml2-devel is earlier than 0:2.6.26-2.1.25.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:37853"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136030" version="1" comment="libxml2-python is earlier than 0:2.6.26-2.1.25.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:37853"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135895" version="1" comment="libxml2 is earlier than 0:2.6.26-2.1.25.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:37853"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126039" version="2" comment="sudo-debuginfo is earlier than 0:1.7.2p1-28.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42464"/>
      <state state_ref="oval:org.mitre.oval:ste:34791"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125109" version="1" comment="sudo is earlier than 0:1.7.2p1-28.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14246"/>
      <state state_ref="oval:org.mitre.oval:ste:34791"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126092" version="1" comment="vixie-cron is earlier than 0:4.1-81.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13978"/>
      <state state_ref="oval:org.mitre.oval:ste:34904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125898" version="1" comment="vixie-cron-debuginfo is earlier than 0:4.1-81.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42247"/>
      <state state_ref="oval:org.mitre.oval:ste:34904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126076" version="1" comment="samba3x-winbind is earlier than 0:3.6.6-0.136.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15095"/>
      <state state_ref="oval:org.mitre.oval:ste:34934"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126025" version="1" comment="samba3x is earlier than 0:3.6.6-0.136.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15124"/>
      <state state_ref="oval:org.mitre.oval:ste:34934"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125923" version="1" comment="samba3x-debuginfo is earlier than 0:3.6.6-0.136.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42526"/>
      <state state_ref="oval:org.mitre.oval:ste:34934"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125808" version="1" comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.136.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15045"/>
      <state state_ref="oval:org.mitre.oval:ste:34934"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125773" version="1" comment="samba3x-common is earlier than 0:3.6.6-0.136.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14673"/>
      <state state_ref="oval:org.mitre.oval:ste:34934"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125737" version="1" comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.136.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15239"/>
      <state state_ref="oval:org.mitre.oval:ste:34934"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125577" version="1" comment="samba3x-doc is earlier than 0:3.6.6-0.136.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14991"/>
      <state state_ref="oval:org.mitre.oval:ste:34934"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125574" version="1" comment="samba3x-client is earlier than 0:3.6.6-0.136.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14854"/>
      <state state_ref="oval:org.mitre.oval:ste:34934"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125294" version="1" comment="samba3x-swat is earlier than 0:3.6.6-0.136.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15202"/>
      <state state_ref="oval:org.mitre.oval:ste:34934"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126040" version="1" comment="kernel-debuginfo is earlier than 0:2.6.18-371.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42117"/>
      <state state_ref="oval:org.mitre.oval:ste:34915"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126033" version="1" comment="kernel-debug is earlier than 0:2.6.18-371.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:34915"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126027" version="1" comment="kernel-xen-debuginfo is earlier than 0:2.6.18-371.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42411"/>
      <state state_ref="oval:org.mitre.oval:ste:34915"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125944" version="1" comment="kernel-PAE is earlier than 0:2.6.18-371.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:34915"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125921" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-371.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:34915"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125918" version="1" comment="kernel-PAE-debuginfo is earlier than 0:2.6.18-371.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42166"/>
      <state state_ref="oval:org.mitre.oval:ste:34915"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125907" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-371.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:34915"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125824" version="1" comment="kernel-headers is earlier than 0:2.6.18-371.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:34915"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125786" version="1" comment="kernel-doc is earlier than 0:2.6.18-371.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:34915"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125763" version="1" comment="kernel is earlier than 0:2.6.18-371.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:34915"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125592" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-371.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:34915"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125588" version="1" comment="kernel-devel is earlier than 0:2.6.18-371.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:34915"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125571" version="1" comment="kernel-xen is earlier than 0:2.6.18-371.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:34915"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125450" version="1" comment="kernel-debug-debuginfo is earlier than 0:2.6.18-371.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42590"/>
      <state state_ref="oval:org.mitre.oval:ste:34915"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125074" version="1" comment="kernel-debuginfo-common is earlier than 0:2.6.18-371.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14853"/>
      <state state_ref="oval:org.mitre.oval:ste:34915"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125920" version="1" comment="php-bcmath is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14639"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125911" version="1" comment="php53-process is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29375"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125902" version="1" comment="php53-pspell is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29208"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125900" version="1" comment="php-zts is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29304"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125888" version="1" comment="php-imap is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14250"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125886" version="1" comment="php-pgsql is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14148"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125877" version="1" comment="php53-pdo is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29253"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125873" version="1" comment="php-xmlrpc is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14445"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125832" version="1" comment="php-dba is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14512"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125814" version="1" comment="php-pdo is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14154"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125813" version="1" comment="php-process is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28714"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125784" version="1" comment="php53-intl is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29195"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125778" version="1" comment="php-enchant is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28929"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125746" version="1" comment="php-snmp is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14508"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125741" version="1" comment="php53-ldap is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29602"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125739" version="1" comment="php53-dba is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28950"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125738" version="1" comment="php-mysql is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14080"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125724" version="1" comment="php53-common is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29562"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125711" version="1" comment="php53-devel is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29547"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125705" version="1" comment="php53-soap is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29455"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125697" version="1" comment="php-xml is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14560"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125683" version="1" comment="php-ldap is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14375"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125661" version="1" comment="php-recode is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29111"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125654" version="1" comment="php-intl is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29069"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125644" version="1" comment="php-fpm is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29228"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125640" version="1" comment="php53-xmlrpc is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29475"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125620" version="1" comment="php-odbc is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14183"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125614" version="1" comment="php-tidy is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28881"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125520" version="1" comment="php53-imap is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29568"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125519" version="1" comment="php53-mysql is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29022"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125516" version="1" comment="php53-pgsql is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29505"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125507" version="1" comment="php-pspell is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29329"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125496" version="1" comment="php53 is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29556"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125461" version="1" comment="php53-cli is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28902"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125455" version="1" comment="php53-odbc is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29337"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125414" version="1" comment="php-cli is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14922"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125409" version="1" comment="php is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14294"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125406" version="1" comment="php-soap is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14366"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125361" version="1" comment="php-common is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14841"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125184" version="1" comment="php53-gd is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29626"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125177" version="1" comment="php-mbstring is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13746"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125173" version="1" comment="php53-mbstring is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29008"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125124" version="1" comment="php-devel is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13492"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125105" version="1" comment="php53-xml is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29235"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125033" version="1" comment="php-gd is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14335"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125011" version="1" comment="php53-snmp is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29427"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124972" version="1" comment="php-embedded is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28613"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124943" version="1" comment="php53-bcmath is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29087"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125390" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.33-1.13.5.0.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:34728"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125380" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.33-1.13.5.0.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:34739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125374" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.33-1.13.5.0.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:34257"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125373" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.33-1.13.5.0.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:34728"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125310" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.33-1.13.5.0.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:34728"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125277" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.33-1.13.5.0.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:34739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125226" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.33-1.13.5.0.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:34257"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125224" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.33-1.13.5.0.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:34728"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125213" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.33-1.13.5.0.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:34257"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125204" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.33-1.13.5.0.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:34739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125178" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.33-1.13.5.0.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:34739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125149" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.33-1.13.5.0.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:34728"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125061" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.33-1.13.5.0.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:34739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124735" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.33-1.13.5.0.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:34257"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124654" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.33-1.13.5.0.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:34257"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125307" version="1" comment="java-1.7.0-openjdk is earlier than 1:1.7.0.71-2.5.3.1.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28860"/>
      <state state_ref="oval:org.mitre.oval:ste:34461"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125228" version="1" comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.71-2.5.3.1.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29000"/>
      <state state_ref="oval:org.mitre.oval:ste:34461"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125095" version="1" comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.71-2.5.3.1.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29032"/>
      <state state_ref="oval:org.mitre.oval:ste:34461"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124937" version="1" comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.71-2.5.3.1.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29256"/>
      <state state_ref="oval:org.mitre.oval:ste:34461"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124403" version="1" comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.71-2.5.3.1.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28946"/>
      <state state_ref="oval:org.mitre.oval:ste:34461"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125259" version="1" comment="thunderbird is earlier than 0:31.2.0-2.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:34711"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125147" version="1" comment="thunderbird is earlier than 0:31.2.0-2.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:34226"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125043" version="1" comment="thunderbird is earlier than 0:31.2.0-3.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:34569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126004" version="1" comment="ccid is earlier than 0:1.3.8-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29294"/>
      <state state_ref="oval:org.mitre.oval:ste:34181"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125480" version="1" comment="ccid-debuginfo is earlier than 0:1.3.8-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41753"/>
      <state state_ref="oval:org.mitre.oval:ste:34181"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141228" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.85-1jpp.3.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:39479"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141206" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.85-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:39349"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141202" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.85-1jpp.3.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14936"/>
      <state state_ref="oval:org.mitre.oval:ste:39479"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141151" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.85-1jpp.3.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:39479"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141147" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.85-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:39349"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141137" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.85-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:39349"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141080" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.85-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:39349"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140941" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.85-1jpp.3.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:39479"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140933" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.85-1jpp.3.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:39479"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140874" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.85-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14936"/>
      <state state_ref="oval:org.mitre.oval:ste:39349"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140660" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.85-1jpp.3.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:39479"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140292" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.85-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:39349"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125368" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.85-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:34801"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125319" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.85-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:34801"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125276" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.85-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:34801"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125249" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.85-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:34801"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125088" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.85-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:34801"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125078" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.85-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14936"/>
      <state state_ref="oval:org.mitre.oval:ste:34801"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126061" version="1" comment="subversion-debuginfo is earlier than 0:1.6.11-12.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42619"/>
      <state state_ref="oval:org.mitre.oval:ste:34919"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126055" version="1" comment="subversion-perl is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14470"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126051" version="1" comment="subversion-kde is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29565"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126034" version="1" comment="subversion is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15298"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126009" version="1" comment="subversion-devel is earlier than 0:1.6.11-12.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14983"/>
      <state state_ref="oval:org.mitre.oval:ste:34919"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126006" version="1" comment="subversion-perl is earlier than 0:1.6.11-12.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14470"/>
      <state state_ref="oval:org.mitre.oval:ste:34919"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125974" version="1" comment="subversion-devel is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14983"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125964" version="1" comment="subversion-debuginfo is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42619"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125958" version="1" comment="subversion-javahl is earlier than 0:1.6.11-12.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15180"/>
      <state state_ref="oval:org.mitre.oval:ste:34919"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125809" version="1" comment="subversion-ruby is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15192"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125681" version="1" comment="mod_dav_svn is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14514"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125525" version="1" comment="subversion-svn2cl is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29417"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125508" version="1" comment="subversion-javahl is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15180"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125411" version="1" comment="mod_dav_svn is earlier than 0:1.6.11-12.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14514"/>
      <state state_ref="oval:org.mitre.oval:ste:34919"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125069" version="1" comment="subversion-gnome is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29010"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125062" version="1" comment="subversion-ruby is earlier than 0:1.6.11-12.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15192"/>
      <state state_ref="oval:org.mitre.oval:ste:34919"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125048" version="1" comment="subversion is earlier than 0:1.6.11-12.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15298"/>
      <state state_ref="oval:org.mitre.oval:ste:34919"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126070" version="1" comment="boost-doc is earlier than 0:1.33.1-15.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3246"/>
      <state state_ref="oval:org.mitre.oval:ste:34502"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126058" version="1" comment="boost-devel is earlier than 0:1.33.1-15.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3351"/>
      <state state_ref="oval:org.mitre.oval:ste:34502"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125852" version="1" comment="boost-debuginfo is earlier than 0:1.33.1-15.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3402"/>
      <state state_ref="oval:org.mitre.oval:ste:34502"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125830" version="1" comment="boost is earlier than 0:1.33.1-15.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3145"/>
      <state state_ref="oval:org.mitre.oval:ste:34502"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125322" version="1" comment="openssl-devel is earlier than 0:0.9.8e-31.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:34486"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125156" version="1" comment="openssl is earlier than 0:0.9.8e-31.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:34486"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125126" version="1" comment="openssl-perl is earlier than 0:0.9.8e-31.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:34486"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126046" version="1" comment="sssd-tools is earlier than 0:1.5.1-70.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29289"/>
      <state state_ref="oval:org.mitre.oval:ste:34890"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125995" version="1" comment="libipa_hbac is earlier than 0:1.5.1-70.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28719"/>
      <state state_ref="oval:org.mitre.oval:ste:34890"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125885" version="1" comment="sssd is earlier than 0:1.5.1-70.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28863"/>
      <state state_ref="oval:org.mitre.oval:ste:34890"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125777" version="1" comment="libipa_hbac-python is earlier than 0:1.5.1-70.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29324"/>
      <state state_ref="oval:org.mitre.oval:ste:34890"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125740" version="1" comment="libipa_hbac-devel is earlier than 0:1.5.1-70.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29283"/>
      <state state_ref="oval:org.mitre.oval:ste:34890"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125564" version="1" comment="sssd-debuginfo is earlier than 0:1.5.1-70.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42579"/>
      <state state_ref="oval:org.mitre.oval:ste:34890"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125482" version="1" comment="sssd-client is earlier than 0:1.5.1-70.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29292"/>
      <state state_ref="oval:org.mitre.oval:ste:34890"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125868" version="1" comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.90.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14873"/>
      <state state_ref="oval:org.mitre.oval:ste:34357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125839" version="1" comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.90.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14353"/>
      <state state_ref="oval:org.mitre.oval:ste:34357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125780" version="1" comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.90.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14653"/>
      <state state_ref="oval:org.mitre.oval:ste:34357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125768" version="1" comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.90.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14794"/>
      <state state_ref="oval:org.mitre.oval:ste:34357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125726" version="1" comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.90.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14842"/>
      <state state_ref="oval:org.mitre.oval:ste:34357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125488" version="1" comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.90.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14667"/>
      <state state_ref="oval:org.mitre.oval:ste:34357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125465" version="1" comment="xorg-x11-server-debuginfo is earlier than 0:1.1.1-48.90.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42697"/>
      <state state_ref="oval:org.mitre.oval:ste:34357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125436" version="1" comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.90.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14709"/>
      <state state_ref="oval:org.mitre.oval:ste:34357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141226" version="1" comment="java-1.7.0-oracle is earlier than 1:1.7.0.72-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28501"/>
      <state state_ref="oval:org.mitre.oval:ste:39094"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141212" version="1" comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.72-1jpp.4.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29211"/>
      <state state_ref="oval:org.mitre.oval:ste:39173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141211" version="1" comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.72-1jpp.4.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28813"/>
      <state state_ref="oval:org.mitre.oval:ste:39173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141191" version="1" comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.72-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28861"/>
      <state state_ref="oval:org.mitre.oval:ste:39094"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141169" version="1" comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.72-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28836"/>
      <state state_ref="oval:org.mitre.oval:ste:39094"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141161" version="1" comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.72-1jpp.4.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28836"/>
      <state state_ref="oval:org.mitre.oval:ste:39173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141116" version="1" comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.72-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29211"/>
      <state state_ref="oval:org.mitre.oval:ste:39094"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140953" version="1" comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.72-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28813"/>
      <state state_ref="oval:org.mitre.oval:ste:39094"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140948" version="1" comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.72-1jpp.4.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29158"/>
      <state state_ref="oval:org.mitre.oval:ste:39173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140918" version="1" comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.72-1jpp.4.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28861"/>
      <state state_ref="oval:org.mitre.oval:ste:39173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140729" version="1" comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.72-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29158"/>
      <state state_ref="oval:org.mitre.oval:ste:39094"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140719" version="1" comment="java-1.7.0-oracle is earlier than 1:1.7.0.72-1jpp.4.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28501"/>
      <state state_ref="oval:org.mitre.oval:ste:39173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125348" version="1" comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.72-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28813"/>
      <state state_ref="oval:org.mitre.oval:ste:34718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125339" version="1" comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.72-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29158"/>
      <state state_ref="oval:org.mitre.oval:ste:34718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125290" version="1" comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.72-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28861"/>
      <state state_ref="oval:org.mitre.oval:ste:34718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125274" version="1" comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.72-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28836"/>
      <state state_ref="oval:org.mitre.oval:ste:34718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125233" version="1" comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.72-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29211"/>
      <state state_ref="oval:org.mitre.oval:ste:34718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124966" version="1" comment="java-1.7.0-oracle is earlier than 1:1.7.0.72-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28501"/>
      <state state_ref="oval:org.mitre.oval:ste:34718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125381" version="1" comment="firefox is earlier than 0:31.2.0-3.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:34688"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125356" version="1" comment="firefox is earlier than 0:31.2.0-3.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:34569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125354" version="1" comment="xulrunner is earlier than 0:31.2.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:34644"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125349" version="1" comment="xulrunner is earlier than 0:31.2.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:34819"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125313" version="1" comment="xulrunner-devel is earlier than 0:31.2.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:34644"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125112" version="1" comment="firefox is earlier than 0:31.2.0-3.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:34242"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125107" version="1" comment="xulrunner-devel is earlier than 0:31.2.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:34819"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125077" version="1" comment="firefox is earlier than 0:31.2.0-3.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:34634"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124713" version="1" comment="firefox is earlier than 0:31.2.0-3.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:34522"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138442" version="1" comment="luci is earlier than 0:0.12.2-81.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14950"/>
      <state state_ref="oval:org.mitre.oval:ste:38465"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138312" version="1" comment="ricci is earlier than 0:0.12.2-81.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14147"/>
      <state state_ref="oval:org.mitre.oval:ste:38465"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123908" version="1" comment="axis is earlier than 0:1.2.1-2jpp.8.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3069"/>
      <state state_ref="oval:org.mitre.oval:ste:34370"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123903" version="1" comment="axis-javadoc is earlier than 0:1.2.1-7.5.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:2320"/>
      <state state_ref="oval:org.mitre.oval:ste:33934"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123895" version="1" comment="axis-javadoc is earlier than 0:1.2.1-2jpp.8.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:2320"/>
      <state state_ref="oval:org.mitre.oval:ste:34370"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123761" version="1" comment="axis is earlier than 0:1.2.1-7.5.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3069"/>
      <state state_ref="oval:org.mitre.oval:ste:33934"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123658" version="1" comment="axis-manual is earlier than 0:1.2.1-7.5.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3255"/>
      <state state_ref="oval:org.mitre.oval:ste:33934"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123598" version="1" comment="axis-manual is earlier than 0:1.2.1-2jpp.8.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3255"/>
      <state state_ref="oval:org.mitre.oval:ste:34370"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125906" version="1" comment="rsyslog5-pgsql is earlier than 0:5.8.12-5.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42664"/>
      <state state_ref="oval:org.mitre.oval:ste:34862"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125903" version="1" comment="rsyslog5-debuginfo is earlier than 0:5.8.12-5.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42408"/>
      <state state_ref="oval:org.mitre.oval:ste:34862"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125854" version="1" comment="rsyslog-debuginfo is earlier than 0:5.8.10-9.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42620"/>
      <state state_ref="oval:org.mitre.oval:ste:34980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125806" version="1" comment="rsyslog5-gnutls is earlier than 0:5.8.12-5.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42650"/>
      <state state_ref="oval:org.mitre.oval:ste:34862"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125803" version="1" comment="rsyslog5-gssapi is earlier than 0:5.8.12-5.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42111"/>
      <state state_ref="oval:org.mitre.oval:ste:34862"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125788" version="1" comment="rsyslog5 is earlier than 0:5.8.12-5.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42572"/>
      <state state_ref="oval:org.mitre.oval:ste:34862"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125716" version="1" comment="rsyslog-gssapi is earlier than 0:5.8.10-9.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29969"/>
      <state state_ref="oval:org.mitre.oval:ste:34980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125650" version="1" comment="rsyslog-relp is earlier than 0:5.8.10-9.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29740"/>
      <state state_ref="oval:org.mitre.oval:ste:34980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125639" version="1" comment="rsyslog5-snmp is earlier than 0:5.8.12-5.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42593"/>
      <state state_ref="oval:org.mitre.oval:ste:34862"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125530" version="1" comment="rsyslog-snmp is earlier than 0:5.8.10-9.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29239"/>
      <state state_ref="oval:org.mitre.oval:ste:34980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125524" version="1" comment="rsyslog is earlier than 0:5.8.10-9.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29962"/>
      <state state_ref="oval:org.mitre.oval:ste:34980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125517" version="1" comment="rsyslog-mysql is earlier than 0:5.8.10-9.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29867"/>
      <state state_ref="oval:org.mitre.oval:ste:34980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125503" version="1" comment="rsyslog-gnutls is earlier than 0:5.8.10-9.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30163"/>
      <state state_ref="oval:org.mitre.oval:ste:34980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125341" version="1" comment="rsyslog-pgsql is earlier than 0:5.8.10-9.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29691"/>
      <state state_ref="oval:org.mitre.oval:ste:34980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125338" version="1" comment="rsyslog5-mysql is earlier than 0:5.8.12-5.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42350"/>
      <state state_ref="oval:org.mitre.oval:ste:34862"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138310" version="1" comment="krb5-debuginfo is earlier than 0:1.6.1-78.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:44140"/>
      <state state_ref="oval:org.mitre.oval:ste:38411"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123887" version="1" comment="krb5-server is earlier than 0:1.6.1-78.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14452"/>
      <state state_ref="oval:org.mitre.oval:ste:34450"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123884" version="1" comment="krb5-workstation is earlier than 0:1.6.1-78.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14279"/>
      <state state_ref="oval:org.mitre.oval:ste:34450"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123870" version="1" comment="krb5-server-ldap is earlier than 0:1.6.1-78.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29451"/>
      <state state_ref="oval:org.mitre.oval:ste:34450"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123866" version="1" comment="krb5-libs is earlier than 0:1.6.1-78.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14395"/>
      <state state_ref="oval:org.mitre.oval:ste:34450"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123687" version="1" comment="krb5-devel is earlier than 0:1.6.1-78.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14100"/>
      <state state_ref="oval:org.mitre.oval:ste:34450"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135359" version="1" comment="nss-debuginfo is earlier than 0:3.16.1-4.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42328"/>
      <state state_ref="oval:org.mitre.oval:ste:37507"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135339" version="1" comment="nss-util-debuginfo is earlier than 0:3.16.2-2.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42869"/>
      <state state_ref="oval:org.mitre.oval:ste:37336"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135333" version="1" comment="nss-softokn-debuginfo is earlier than 0:3.16.2-2.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43053"/>
      <state state_ref="oval:org.mitre.oval:ste:37336"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135328" version="1" comment="nss-softokn-debuginfo is earlier than 0:3.14.3-12.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43053"/>
      <state state_ref="oval:org.mitre.oval:ste:36556"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135234" version="1" comment="nss-debuginfo is earlier than 0:3.16.1-7.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42328"/>
      <state state_ref="oval:org.mitre.oval:ste:37389"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135090" version="1" comment="nss-util-debuginfo is earlier than 0:3.16.1-2.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42869"/>
      <state state_ref="oval:org.mitre.oval:ste:36573"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:134839" version="1" comment="nss-debuginfo is earlier than 0:3.16.2-7.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42328"/>
      <state state_ref="oval:org.mitre.oval:ste:37178"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124011" version="1" comment="nss-softokn is earlier than 0:3.16.2-2.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29421"/>
      <state state_ref="oval:org.mitre.oval:ste:34396"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123982" version="1" comment="nss-softokn-freebl is earlier than 0:3.16.2-2.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29159"/>
      <state state_ref="oval:org.mitre.oval:ste:34396"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123968" version="1" comment="nss-softokn-freebl-devel is earlier than 0:3.14.3-12.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29515"/>
      <state state_ref="oval:org.mitre.oval:ste:34365"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123954" version="1" comment="nss-tools is earlier than 0:3.16.1-7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:33988"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123944" version="1" comment="nss-tools is earlier than 0:3.16.1-4.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:34244"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123916" version="1" comment="nss-softokn-devel is earlier than 0:3.14.3-12.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29485"/>
      <state state_ref="oval:org.mitre.oval:ste:34365"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123897" version="1" comment="nss is earlier than 0:3.16.1-4.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:34244"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123896" version="1" comment="nss-softokn-freebl-devel is earlier than 0:3.16.2-2.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29515"/>
      <state state_ref="oval:org.mitre.oval:ste:34396"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123883" version="1" comment="nss-pkcs11-devel is earlier than 0:3.16.1-7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:33988"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123878" version="1" comment="nss-devel is earlier than 0:3.16.1-4.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:34244"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123873" version="1" comment="nss-devel is earlier than 0:3.16.2-7.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:34353"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123871" version="1" comment="nss-softokn-freebl is earlier than 0:3.14.3-12.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29159"/>
      <state state_ref="oval:org.mitre.oval:ste:34365"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123851" version="1" comment="nss-tools is earlier than 0:3.16.2-7.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:34353"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123832" version="1" comment="nss-devel is earlier than 0:3.16.1-7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:33988"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123826" version="1" comment="nss is earlier than 0:3.16.1-7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:33988"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123805" version="1" comment="nss-util is earlier than 0:3.16.1-2.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29019"/>
      <state state_ref="oval:org.mitre.oval:ste:34415"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123793" version="1" comment="nss-util is earlier than 0:3.16.2-2.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29019"/>
      <state state_ref="oval:org.mitre.oval:ste:34396"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123771" version="1" comment="nss-sysinit is earlier than 0:3.16.2-7.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28504"/>
      <state state_ref="oval:org.mitre.oval:ste:34353"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123768" version="1" comment="nss-util-devel is earlier than 0:3.16.1-2.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29207"/>
      <state state_ref="oval:org.mitre.oval:ste:34415"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123719" version="1" comment="nss-softokn-devel is earlier than 0:3.16.2-2.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29485"/>
      <state state_ref="oval:org.mitre.oval:ste:34396"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123673" version="1" comment="nss-softokn is earlier than 0:3.14.3-12.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29421"/>
      <state state_ref="oval:org.mitre.oval:ste:34365"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123650" version="1" comment="nss-pkcs11-devel is earlier than 0:3.16.2-7.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:34353"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123492" version="1" comment="nss is earlier than 0:3.16.2-7.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:34353"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123201" version="1" comment="nss-sysinit is earlier than 0:3.16.1-7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28504"/>
      <state state_ref="oval:org.mitre.oval:ste:33988"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123190" version="1" comment="nss-util-devel is earlier than 0:3.16.2-2.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29207"/>
      <state state_ref="oval:org.mitre.oval:ste:34396"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123032" version="1" comment="nss-pkcs11-devel is earlier than 0:3.16.1-4.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:34244"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137941" version="1" comment="krb5-debuginfo is earlier than 0:1.6.1-80.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:44140"/>
      <state state_ref="oval:org.mitre.oval:ste:38424"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123986" version="1" comment="krb5-workstation is earlier than 0:1.6.1-80.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14279"/>
      <state state_ref="oval:org.mitre.oval:ste:33689"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123984" version="1" comment="krb5-server-ldap is earlier than 0:1.6.1-80.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29451"/>
      <state state_ref="oval:org.mitre.oval:ste:33689"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123922" version="1" comment="krb5-server is earlier than 0:1.6.1-80.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14452"/>
      <state state_ref="oval:org.mitre.oval:ste:33689"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123511" version="1" comment="krb5-devel is earlier than 0:1.6.1-80.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14100"/>
      <state state_ref="oval:org.mitre.oval:ste:33689"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122986" version="1" comment="krb5-libs is earlier than 0:1.6.1-80.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14395"/>
      <state state_ref="oval:org.mitre.oval:ste:33689"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123117" version="1" comment="nss-tools is earlier than 0:3.16.1-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:33566"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123083" version="1" comment="nss-devel is earlier than 0:3.16.1-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:33566"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122829" version="1" comment="nss-pkcs11-devel is earlier than 0:3.16.1-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:33566"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122742" version="1" comment="nss is earlier than 0:3.16.1-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:33566"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122939" version="1" comment="squid is earlier than 7:3.1.10-22.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14403"/>
      <state state_ref="oval:org.mitre.oval:ste:33869"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122890" version="1" comment="squid is earlier than 7:2.6.STABLE21-7.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14403"/>
      <state state_ref="oval:org.mitre.oval:ste:33754"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123869" version="1" comment="flash-plugin is earlier than 0:11.2.202.406-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:34422"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123356" version="1" comment="flash-plugin is earlier than 0:11.2.202.406-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:34134"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123229" version="1" comment="automake is earlier than 0:1.9.6-3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:2248"/>
      <state state_ref="oval:org.mitre.oval:ste:34143"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123180" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.18-371.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:33589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123141" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-371.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:33589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123094" version="1" comment="kernel-headers is earlier than 0:2.6.18-371.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:33589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122988" version="1" comment="kernel is earlier than 0:2.6.18-371.12.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:33589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122936" version="1" comment="kernel-devel is earlier than 0:2.6.18-371.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:33589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122921" version="1" comment="kernel-xen is earlier than 0:2.6.18-371.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:33589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122789" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-371.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:33589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122733" version="1" comment="kernel-PAE is earlier than 0:2.6.18-371.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:33589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122732" version="1" comment="kernel-debug is earlier than 0:2.6.18-371.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:33589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122572" version="1" comment="kernel-kdump is earlier than 0:2.6.18-371.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:33589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122313" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-371.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:33589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122206" version="1" comment="kernel-doc is earlier than 0:2.6.18-371.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:33589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123949" version="1" comment="bash is earlier than 0:3.2-33.el5_10.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3150"/>
      <state state_ref="oval:org.mitre.oval:ste:34344"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123900" version="1" comment="bash-doc is earlier than 0:4.2.45-5.el7_0.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41925"/>
      <state state_ref="oval:org.mitre.oval:ste:33655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123544" version="1" comment="bash is earlier than 0:4.1.2-15.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3150"/>
      <state state_ref="oval:org.mitre.oval:ste:34343"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123527" version="1" comment="bash is earlier than 0:4.2.45-5.el7_0.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3150"/>
      <state state_ref="oval:org.mitre.oval:ste:33655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123461" version="1" comment="bash-doc is earlier than 0:4.1.2-15.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41925"/>
      <state state_ref="oval:org.mitre.oval:ste:34343"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123086" version="1" comment="bash is earlier than 0:3.2-33.el5_11.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3150"/>
      <state state_ref="oval:org.mitre.oval:ste:34448"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123170" version="1" comment="xulrunner-devel is earlier than 0:24.8.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:33841"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123084" version="1" comment="firefox is earlier than 0:24.8.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:33981"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123047" version="1" comment="firefox is earlier than 0:24.8.0-2.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:34014"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122891" version="1" comment="firefox is earlier than 0:24.8.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:33841"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122877" version="1" comment="xulrunner-devel is earlier than 0:24.8.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:33779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122875" version="1" comment="xulrunner is earlier than 0:24.8.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:33779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122819" version="1" comment="firefox is earlier than 0:24.8.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:33779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122772" version="1" comment="xulrunner is earlier than 0:24.8.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:33841"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122594" version="1" comment="firefox is earlier than 0:24.8.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:33957"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122510" version="1" comment="firefox is earlier than 0:24.8.0-2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:33550"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123152" version="1" comment="thunderbird is earlier than 0:24.8.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:33957"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123029" version="1" comment="thunderbird is earlier than 0:24.8.0-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:34090"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122969" version="1" comment="thunderbird is earlier than 0:24.8.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:33981"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122759" version="1" comment="thunderbird is earlier than 0:24.8.0-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:33984"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123953" version="1" comment="bash is earlier than 0:3.2-33.el5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3150"/>
      <state state_ref="oval:org.mitre.oval:ste:34205"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123932" version="1" comment="bash is earlier than 0:4.1.2-15.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3150"/>
      <state state_ref="oval:org.mitre.oval:ste:34361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123926" version="1" comment="bash is earlier than 0:4.2.45-5.el7_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3150"/>
      <state state_ref="oval:org.mitre.oval:ste:34132"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123825" version="1" comment="bash-doc is earlier than 0:4.2.45-5.el7_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41925"/>
      <state state_ref="oval:org.mitre.oval:ste:34132"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123696" version="1" comment="bash-doc is earlier than 0:4.1.2-15.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41925"/>
      <state state_ref="oval:org.mitre.oval:ste:34361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123818" version="1" comment="jakarta-commons-httpclient is earlier than 1:3.0-7jpp.4.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29187"/>
      <state state_ref="oval:org.mitre.oval:ste:34275"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123817" version="1" comment="jakarta-commons-httpclient-manual is earlier than 1:3.1-16.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29053"/>
      <state state_ref="oval:org.mitre.oval:ste:34438"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123816" version="1" comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.0-7jpp.4.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29165"/>
      <state state_ref="oval:org.mitre.oval:ste:34275"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123792" version="1" comment="jakarta-commons-httpclient is earlier than 1:3.1-16.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29187"/>
      <state state_ref="oval:org.mitre.oval:ste:34438"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123791" version="1" comment="jakarta-commons-httpclient-manual is earlier than 1:3.0-7jpp.4.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29053"/>
      <state state_ref="oval:org.mitre.oval:ste:34275"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123770" version="1" comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.1-16.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29165"/>
      <state state_ref="oval:org.mitre.oval:ste:34438"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123758" version="1" comment="jakarta-commons-httpclient-manual is earlier than 1:3.1-0.9.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29053"/>
      <state state_ref="oval:org.mitre.oval:ste:34285"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123708" version="1" comment="jakarta-commons-httpclient-demo is earlier than 1:3.0-7jpp.4.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29059"/>
      <state state_ref="oval:org.mitre.oval:ste:34275"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123604" version="1" comment="jakarta-commons-httpclient-demo is earlier than 1:3.1-0.9.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29059"/>
      <state state_ref="oval:org.mitre.oval:ste:34285"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123283" version="1" comment="jakarta-commons-httpclient-demo is earlier than 1:3.1-16.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29059"/>
      <state state_ref="oval:org.mitre.oval:ste:34438"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123167" version="1" comment="jakarta-commons-httpclient is earlier than 1:3.1-0.9.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29187"/>
      <state state_ref="oval:org.mitre.oval:ste:34285"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122896" version="1" comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.1-0.9.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29165"/>
      <state state_ref="oval:org.mitre.oval:ste:34285"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123831" version="1" comment="procmail is earlier than 0:3.22-17.1.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42185"/>
      <state state_ref="oval:org.mitre.oval:ste:34013"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123631" version="1" comment="procmail is earlier than 0:3.22-25.1.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42185"/>
      <state state_ref="oval:org.mitre.oval:ste:34274"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123381" version="1" comment="procmail is earlier than 0:3.22-34.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42185"/>
      <state state_ref="oval:org.mitre.oval:ste:34287"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123250" version="1" comment="procmail is earlier than 0:3.22-17.1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42185"/>
      <state state_ref="oval:org.mitre.oval:ste:34303"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138133" version="1" comment="nss-debuginfo is earlier than 0:3.16.1-2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42328"/>
      <state state_ref="oval:org.mitre.oval:ste:38263"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123864" version="1" comment="nss-devel is earlier than 0:3.16.1-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:34188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123769" version="1" comment="nss-pkcs11-devel is earlier than 0:3.16.1-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:34188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123723" version="1" comment="nss is earlier than 0:3.16.1-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:34188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123383" version="1" comment="nss-tools is earlier than 0:3.16.1-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:34188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125490" version="1" comment="wireshark-gnome is earlier than 0:1.0.15-7.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14663"/>
      <state state_ref="oval:org.mitre.oval:ste:34742"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125413" version="1" comment="wireshark is earlier than 0:1.0.15-7.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14711"/>
      <state state_ref="oval:org.mitre.oval:ste:34742"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125028" version="1" comment="wireshark-debuginfo is earlier than 0:1.0.15-7.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42668"/>
      <state state_ref="oval:org.mitre.oval:ste:34742"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122651" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:33386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122617" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:33386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122592" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:33386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122553" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:33675"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122541" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:33675"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122517" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:33675"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122498" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:33675"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122462" version="1" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15027"/>
      <state state_ref="oval:org.mitre.oval:ste:33675"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122398" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:33675"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122357" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:33386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122289" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:33386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122234" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:33675"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121990" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:33386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121901" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:33386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121689" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:33675"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123079" version="1" comment="nscd is earlier than 0:2.17-55.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14360"/>
      <state state_ref="oval:org.mitre.oval:ste:33765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123073" version="1" comment="glibc-headers is earlier than 0:2.12-1.132.el6_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13936"/>
      <state state_ref="oval:org.mitre.oval:ste:33333"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123071" version="1" comment="nscd is earlier than 0:2.5-118.el5_10.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14360"/>
      <state state_ref="oval:org.mitre.oval:ste:33904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123069" version="1" comment="glibc-headers is earlier than 0:2.5-118.el5_10.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13936"/>
      <state state_ref="oval:org.mitre.oval:ste:33904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123068" version="1" comment="glibc-devel is earlier than 0:2.12-1.132.el6_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14346"/>
      <state state_ref="oval:org.mitre.oval:ste:33333"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123059" version="1" comment="glibc-devel is earlier than 0:2.17-55.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14346"/>
      <state state_ref="oval:org.mitre.oval:ste:33765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123035" version="1" comment="glibc is earlier than 0:2.17-55.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14142"/>
      <state state_ref="oval:org.mitre.oval:ste:33765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123024" version="1" comment="glibc-devel is earlier than 0:2.5-118.el5_10.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14346"/>
      <state state_ref="oval:org.mitre.oval:ste:33904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123014" version="1" comment="glibc-static is earlier than 0:2.17-55.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30224"/>
      <state state_ref="oval:org.mitre.oval:ste:33765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122956" version="1" comment="glibc is earlier than 0:2.5-118.el5_10.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14142"/>
      <state state_ref="oval:org.mitre.oval:ste:33904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122938" version="1" comment="glibc-utils is earlier than 0:2.17-55.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14059"/>
      <state state_ref="oval:org.mitre.oval:ste:33765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122909" version="1" comment="nscd is earlier than 0:2.12-1.132.el6_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14360"/>
      <state state_ref="oval:org.mitre.oval:ste:33333"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122887" version="1" comment="glibc is earlier than 0:2.12-1.132.el6_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14142"/>
      <state state_ref="oval:org.mitre.oval:ste:33333"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122779" version="1" comment="glibc-utils is earlier than 0:2.12-1.132.el6_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14059"/>
      <state state_ref="oval:org.mitre.oval:ste:33333"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122739" version="1" comment="glibc-common is earlier than 0:2.12-1.132.el6_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14374"/>
      <state state_ref="oval:org.mitre.oval:ste:33333"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122669" version="1" comment="glibc-utils is earlier than 0:2.5-118.el5_10.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14059"/>
      <state state_ref="oval:org.mitre.oval:ste:33904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122535" version="1" comment="glibc-common is earlier than 0:2.17-55.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14374"/>
      <state state_ref="oval:org.mitre.oval:ste:33765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122432" version="1" comment="glibc-headers is earlier than 0:2.17-55.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13936"/>
      <state state_ref="oval:org.mitre.oval:ste:33765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122402" version="1" comment="glibc-static is earlier than 0:2.12-1.132.el6_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30224"/>
      <state state_ref="oval:org.mitre.oval:ste:33333"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122380" version="1" comment="glibc-common is earlier than 0:2.5-118.el5_10.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14374"/>
      <state state_ref="oval:org.mitre.oval:ste:33904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122600" version="1" comment="flash-plugin is earlier than 0:11.2.202.400-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:33310"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121704" version="1" comment="flash-plugin is earlier than 0:11.2.202.400-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:33468"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122687" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:33188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122671" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:33188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122656" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:33188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122629" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:33472"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122607" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:33472"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122596" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:33188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122566" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:33472"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122552" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:33472"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122509" version="1" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14643"/>
      <state state_ref="oval:org.mitre.oval:ste:33188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122347" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:33472"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122275" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:33472"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122192" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:33188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122123" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:33188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121907" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:33188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121790" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:33472"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122697" version="1" comment="openssl is earlier than 0:0.9.8e-27.el5_10.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:33717"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122582" version="1" comment="openssl-perl is earlier than 0:0.9.8e-27.el5_10.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:33717"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122208" version="1" comment="openssl-devel is earlier than 0:0.9.8e-27.el5_10.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:33717"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122529" version="1" comment="php-fpm is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29228"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122521" version="1" comment="php-bcmath is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14639"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122491" version="1" comment="php-imap is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14250"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122483" version="1" comment="php-enchant is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28929"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122478" version="1" comment="php-pgsql is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14148"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122469" version="1" comment="php-intl is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29069"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122450" version="1" comment="php-xml is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14560"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122446" version="1" comment="php-process is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28714"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122442" version="1" comment="php53-dba is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28950"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122423" version="1" comment="php-soap is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14366"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122422" version="1" comment="php53-bcmath is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29087"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122396" version="1" comment="php-common is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14841"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122386" version="1" comment="php53-process is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29375"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122385" version="1" comment="php53-gd is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29626"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122383" version="1" comment="php53-ldap is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29602"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122382" version="1" comment="php-recode is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29111"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122373" version="1" comment="php-xmlrpc is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14445"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122364" version="1" comment="php53-devel is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29547"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122355" version="1" comment="php-zts is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29304"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122353" version="1" comment="php-mbstring is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13746"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122302" version="1" comment="php53-pgsql is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29505"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122300" version="1" comment="php53-intl is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29195"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122293" version="1" comment="php-ldap is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14375"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122243" version="1" comment="php53-odbc is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29337"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122240" version="1" comment="php-cli is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14922"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122239" version="1" comment="php-odbc is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14183"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122231" version="1" comment="php-snmp is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14508"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122213" version="1" comment="php53-common is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29562"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122205" version="1" comment="php53-mbstring is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29008"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122144" version="1" comment="php is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14294"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122138" version="1" comment="php53-xml is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29235"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122090" version="1" comment="php53-mysql is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29022"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122085" version="1" comment="php53-imap is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29568"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122067" version="1" comment="php-dba is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14512"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122063" version="1" comment="php53-snmp is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29427"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122020" version="1" comment="php-devel is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13492"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122000" version="1" comment="php-pspell is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29329"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121951" version="1" comment="php-mysql is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14080"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121863" version="1" comment="php53-soap is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29455"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121848" version="1" comment="php53 is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29556"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121844" version="1" comment="php53-pspell is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29208"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121820" version="1" comment="php53-pdo is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29253"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121691" version="1" comment="php-embedded is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28613"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121548" version="1" comment="php-tidy is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28881"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121534" version="1" comment="php-pdo is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14154"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121529" version="1" comment="php-gd is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14335"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121506" version="1" comment="php53-cli is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28902"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121502" version="1" comment="php53-xmlrpc is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29475"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121478" version="1" comment="yum-updatesd is earlier than 1:0.9-6.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41504"/>
      <state state_ref="oval:org.mitre.oval:ste:33439"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122672" version="1" comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29064"/>
      <state state_ref="oval:org.mitre.oval:ste:33654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122662" version="1" comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29376"/>
      <state state_ref="oval:org.mitre.oval:ste:33654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122622" version="1" comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29364"/>
      <state state_ref="oval:org.mitre.oval:ste:33174"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122550" version="1" comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29107"/>
      <state state_ref="oval:org.mitre.oval:ste:33654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122508" version="1" comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29064"/>
      <state state_ref="oval:org.mitre.oval:ste:33174"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122504" version="1" comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29107"/>
      <state state_ref="oval:org.mitre.oval:ste:33174"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122424" version="1" comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29376"/>
      <state state_ref="oval:org.mitre.oval:ste:33174"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122406" version="1" comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28520"/>
      <state state_ref="oval:org.mitre.oval:ste:33174"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122312" version="1" comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29364"/>
      <state state_ref="oval:org.mitre.oval:ste:33654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122155" version="1" comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28974"/>
      <state state_ref="oval:org.mitre.oval:ste:33174"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122134" version="1" comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28520"/>
      <state state_ref="oval:org.mitre.oval:ste:33654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122122" version="1" comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28974"/>
      <state state_ref="oval:org.mitre.oval:ste:33654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138426" version="1" comment="bind97-debuginfo is earlier than 32:9.7.0-21.P2.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:44061"/>
      <state state_ref="oval:org.mitre.oval:ste:37573"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123907" version="1" comment="bind97 is earlier than 32:9.7.0-21.P2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28886"/>
      <state state_ref="oval:org.mitre.oval:ste:34453"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123862" version="1" comment="bind97-utils is earlier than 32:9.7.0-21.P2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28577"/>
      <state state_ref="oval:org.mitre.oval:ste:34453"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123810" version="1" comment="bind97-chroot is earlier than 32:9.7.0-21.P2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29448"/>
      <state state_ref="oval:org.mitre.oval:ste:34453"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123726" version="1" comment="bind97-libs is earlier than 32:9.7.0-21.P2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29535"/>
      <state state_ref="oval:org.mitre.oval:ste:34453"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123370" version="1" comment="bind97-devel is earlier than 32:9.7.0-21.P2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29237"/>
      <state state_ref="oval:org.mitre.oval:ste:34453"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116305" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.81-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:31792"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116089" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.81-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:32037"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116084" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.81-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:32037"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116078" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.81-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37441"/>
      <state state_ref="oval:org.mitre.oval:ste:31792"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116062" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.81-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:32037"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115789" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.81-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:32037"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115505" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.81-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37441"/>
      <state state_ref="oval:org.mitre.oval:ste:32037"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115401" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.81-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:32037"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115370" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.81-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:31792"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115363" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.81-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:31792"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115322" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.81-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:31792"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115315" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.81-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:31792"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116354" version="1" comment="httpd-devel is earlier than 0:2.2.15-31.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37757"/>
      <state state_ref="oval:org.mitre.oval:ste:31991"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116334" version="1" comment="httpd-tools is earlier than 0:2.2.15-31.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29273"/>
      <state state_ref="oval:org.mitre.oval:ste:32006"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116330" version="1" comment="mod_ssl is earlier than 1:2.2.15-31.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:31706"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116323" version="1" comment="httpd-manual is earlier than 0:2.2.15-31.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:31991"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116289" version="1" comment="mod_ssl is earlier than 1:2.2.15-31.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:32021"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116271" version="1" comment="mod_ssl is earlier than 1:2.2.3-87.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:31977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116217" version="1" comment="httpd is earlier than 0:2.2.15-31.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:31991"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116210" version="1" comment="httpd-devel is earlier than 0:2.2.3-87.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37757"/>
      <state state_ref="oval:org.mitre.oval:ste:31982"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116201" version="1" comment="httpd-manual is earlier than 0:2.2.3-87.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:31982"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116196" version="1" comment="mod_ssl is earlier than 1:2.2.3-87.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:32177"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116175" version="1" comment="httpd is earlier than 0:2.2.3-87.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:31982"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116136" version="1" comment="httpd-devel is earlier than 0:2.2.15-31.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37757"/>
      <state state_ref="oval:org.mitre.oval:ste:32006"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116114" version="1" comment="httpd-manual is earlier than 0:2.2.3-87.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:32169"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115938" version="1" comment="httpd is earlier than 0:2.2.3-87.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:32169"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115768" version="1" comment="httpd-tools is earlier than 0:2.2.15-31.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29273"/>
      <state state_ref="oval:org.mitre.oval:ste:31991"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115650" version="1" comment="httpd is earlier than 0:2.2.15-31.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:32006"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115382" version="1" comment="httpd-manual is earlier than 0:2.2.15-31.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:32006"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115372" version="1" comment="httpd-devel is earlier than 0:2.2.3-87.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37757"/>
      <state state_ref="oval:org.mitre.oval:ste:32169"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116211" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-6.1.13.4.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:31388"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116193" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-6.1.13.4.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37884"/>
      <state state_ref="oval:org.mitre.oval:ste:31743"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116192" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-6.1.13.4.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:31388"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116179" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-6.1.13.4.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37884"/>
      <state state_ref="oval:org.mitre.oval:ste:31388"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116166" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-6.1.13.4.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:31600"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116148" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-6.1.13.4.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:31743"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116146" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-6.1.13.4.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38018"/>
      <state state_ref="oval:org.mitre.oval:ste:31743"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116140" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-6.1.13.4.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37884"/>
      <state state_ref="oval:org.mitre.oval:ste:31600"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116107" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-6.1.13.4.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:31388"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116093" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-6.1.13.4.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:31743"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116029" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-6.1.13.4.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38018"/>
      <state state_ref="oval:org.mitre.oval:ste:31388"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115888" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-6.1.13.4.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:31743"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115881" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-6.1.13.4.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:31600"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115804" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-6.1.13.4.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:31600"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115700" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-6.1.13.4.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38018"/>
      <state state_ref="oval:org.mitre.oval:ste:31600"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116306" version="1" comment="nspr-devel is earlier than 0:4.10.6-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15145"/>
      <state state_ref="oval:org.mitre.oval:ste:31916"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116285" version="1" comment="nss-devel is earlier than 0:3.15.3-7.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:32017"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116219" version="1" comment="nss-tools is earlier than 0:3.15.4-7.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:31505"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116165" version="1" comment="nss is earlier than 0:3.15.4-7.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:36815"/>
      <state state_ref="oval:org.mitre.oval:ste:31505"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116149" version="1" comment="nss-sysinit is earlier than 0:3.15.4-7.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38151"/>
      <state state_ref="oval:org.mitre.oval:ste:31505"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116056" version="1" comment="nss-devel is earlier than 0:3.15.4-7.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:31505"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116024" version="1" comment="nspr-devel is earlier than 0:4.10.6-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15145"/>
      <state state_ref="oval:org.mitre.oval:ste:31969"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116012" version="1" comment="nspr is earlier than 0:4.10.6-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14745"/>
      <state state_ref="oval:org.mitre.oval:ste:31916"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115983" version="1" comment="nss is earlier than 0:3.15.3-7.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:36815"/>
      <state state_ref="oval:org.mitre.oval:ste:32017"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115928" version="1" comment="nss-pkcs11-devel is earlier than 0:3.15.4-7.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:31505"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115855" version="1" comment="nspr is earlier than 0:4.10.6-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14745"/>
      <state state_ref="oval:org.mitre.oval:ste:31969"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115735" version="1" comment="nss-tools is earlier than 0:3.15.3-7.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:32017"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115635" version="1" comment="nss-pkcs11-devel is earlier than 0:3.15.3-7.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:32017"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116208" version="1" comment="java-1.7.0-oracle is earlier than 1:1.7.0.65-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38120"/>
      <state state_ref="oval:org.mitre.oval:ste:31957"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116159" version="1" comment="java-1.7.0-oracle is earlier than 1:1.7.0.65-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38120"/>
      <state state_ref="oval:org.mitre.oval:ste:31962"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116130" version="1" comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.65-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38181"/>
      <state state_ref="oval:org.mitre.oval:ste:31957"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116045" version="1" comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.65-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29211"/>
      <state state_ref="oval:org.mitre.oval:ste:31957"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116028" version="1" comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.65-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28836"/>
      <state state_ref="oval:org.mitre.oval:ste:31957"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115996" version="1" comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.65-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28861"/>
      <state state_ref="oval:org.mitre.oval:ste:31957"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115979" version="1" comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.65-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29158"/>
      <state state_ref="oval:org.mitre.oval:ste:31957"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115925" version="1" comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.65-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28861"/>
      <state state_ref="oval:org.mitre.oval:ste:31962"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115810" version="1" comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.65-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29158"/>
      <state state_ref="oval:org.mitre.oval:ste:31962"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115721" version="1" comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.65-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38181"/>
      <state state_ref="oval:org.mitre.oval:ste:31962"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115708" version="1" comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.65-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28836"/>
      <state state_ref="oval:org.mitre.oval:ste:31962"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115380" version="1" comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.65-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29211"/>
      <state state_ref="oval:org.mitre.oval:ste:31962"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115998" version="1" comment="libsmbclient-devel is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15335"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115908" version="1" comment="libsmbclient is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37433"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115904" version="1" comment="samba-winbind-clients is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38277"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115866" version="1" comment="samba3x-client is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14854"/>
      <state state_ref="oval:org.mitre.oval:ste:31400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115854" version="1" comment="samba-winbind is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29389"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115828" version="1" comment="samba3x-winbind is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15095"/>
      <state state_ref="oval:org.mitre.oval:ste:31400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115827" version="1" comment="samba3x-doc is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14991"/>
      <state state_ref="oval:org.mitre.oval:ste:31400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115794" version="1" comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28660"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115752" version="1" comment="samba3x-common is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14673"/>
      <state state_ref="oval:org.mitre.oval:ste:31400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115719" version="1" comment="samba-winbind-devel is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29445"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115699" version="1" comment="samba-doc is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37787"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115671" version="1" comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15239"/>
      <state state_ref="oval:org.mitre.oval:ste:31400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115588" version="1" comment="samba is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13931"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115545" version="1" comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15045"/>
      <state state_ref="oval:org.mitre.oval:ste:31400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115415" version="1" comment="samba-domainjoin-gui is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28867"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115293" version="1" comment="samba3x is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15124"/>
      <state state_ref="oval:org.mitre.oval:ste:31400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115213" version="1" comment="samba3x-swat is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15202"/>
      <state state_ref="oval:org.mitre.oval:ste:31400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115108" version="1" comment="samba-client is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13861"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115089" version="1" comment="samba-swat is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13707"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115002" version="1" comment="samba-common is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38329"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116333" version="1" comment="firefox is earlier than 0:24.7.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:32072"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116303" version="1" comment="firefox is earlier than 0:24.7.0-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:32159"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116256" version="1" comment="firefox is earlier than 0:24.7.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:31838"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116167" version="1" comment="firefox is earlier than 0:24.7.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:31784"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116099" version="1" comment="firefox is earlier than 0:24.7.0-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:31874"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116085" version="1" comment="firefox is earlier than 0:24.7.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:31643"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115931" version="1" comment="xulrunner-devel is earlier than 0:24.7.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:31784"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115784" version="1" comment="xulrunner is earlier than 0:24.7.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:31784"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115740" version="1" comment="xulrunner is earlier than 0:24.7.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:31643"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115371" version="1" comment="xulrunner-devel is earlier than 0:24.7.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:31643"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116367" version="1" comment="kernel-xen is earlier than 0:2.6.18-371.11.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:32149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116356" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-371.11.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:35004"/>
      <state state_ref="oval:org.mitre.oval:ste:32149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116342" version="1" comment="kernel-debug is earlier than 0:2.6.18-371.11.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:32149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116341" version="1" comment="kernel is earlier than 0:2.6.18-371.11.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:32149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116237" version="1" comment="kernel-kdump is earlier than 0:2.6.18-371.11.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37985"/>
      <state state_ref="oval:org.mitre.oval:ste:32149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116104" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-371.11.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:32149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116067" version="1" comment="kernel-PAE is earlier than 0:2.6.18-371.11.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:32149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116063" version="1" comment="kernel-devel is earlier than 0:2.6.18-371.11.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:32149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116021" version="1" comment="kernel-headers is earlier than 0:2.6.18-371.11.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38456"/>
      <state state_ref="oval:org.mitre.oval:ste:32149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116015" version="1" comment="kernel-doc is earlier than 0:2.6.18-371.11.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:32149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115984" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.18-371.11.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:32149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115950" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-371.11.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:32149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116040" version="1" comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.65-2.5.1.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29256"/>
      <state state_ref="oval:org.mitre.oval:ste:31908"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115975" version="1" comment="java-1.7.0-openjdk is earlier than 1:1.7.0.65-2.5.1.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28860"/>
      <state state_ref="oval:org.mitre.oval:ste:31908"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115857" version="1" comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.65-2.5.1.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28946"/>
      <state state_ref="oval:org.mitre.oval:ste:31908"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115402" version="1" comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.65-2.5.1.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29000"/>
      <state state_ref="oval:org.mitre.oval:ste:31908"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115056" version="1" comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.65-2.5.1.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29032"/>
      <state state_ref="oval:org.mitre.oval:ste:31908"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116066" version="1" comment="flash-plugin is earlier than 0:11.2.202.394-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:31847"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116002" version="1" comment="flash-plugin is earlier than 0:11.2.202.394-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:31880"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116259" version="2" comment="samba3x-doc is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14991"/>
      <state state_ref="oval:org.mitre.oval:ste:31718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116253" version="2" comment="samba3x-client is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14854"/>
      <state state_ref="oval:org.mitre.oval:ste:31718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116223" version="2" comment="samba is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13931"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116200" version="2" comment="samba-winbind-clients is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38277"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116190" version="2" comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15045"/>
      <state state_ref="oval:org.mitre.oval:ste:31718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116128" version="2" comment="samba-domainjoin-gui is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28867"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116106" version="2" comment="samba-swat is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13707"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116097" version="2" comment="samba-doc is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37787"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116076" version="2" comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15239"/>
      <state state_ref="oval:org.mitre.oval:ste:31718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116003" version="2" comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28660"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115986" version="2" comment="samba-winbind is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29389"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115965" version="2" comment="samba3x-winbind is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15095"/>
      <state state_ref="oval:org.mitre.oval:ste:31718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115954" version="2" comment="samba-client is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13861"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115949" version="2" comment="libsmbclient-devel is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15335"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115887" version="2" comment="libsmbclient is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37433"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115686" version="2" comment="samba3x-swat is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15202"/>
      <state state_ref="oval:org.mitre.oval:ste:31718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115675" version="2" comment="samba-winbind-devel is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29445"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115479" version="2" comment="samba3x is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15124"/>
      <state state_ref="oval:org.mitre.oval:ste:31718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115374" version="2" comment="samba3x-common is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14673"/>
      <state state_ref="oval:org.mitre.oval:ste:31718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115270" version="2" comment="samba-common is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38329"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116108" version="2" comment="java-1.7.0-openjdk is earlier than 1:1.7.0.65-2.5.1.2.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28860"/>
      <state state_ref="oval:org.mitre.oval:ste:31084"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116065" version="2" comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.65-2.5.1.2.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29000"/>
      <state state_ref="oval:org.mitre.oval:ste:31084"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116014" version="2" comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.65-2.5.1.2.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29032"/>
      <state state_ref="oval:org.mitre.oval:ste:31084"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115860" version="2" comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.65-2.5.1.2.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29256"/>
      <state state_ref="oval:org.mitre.oval:ste:31084"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115774" version="2" comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.65-2.5.1.2.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28946"/>
      <state state_ref="oval:org.mitre.oval:ste:31084"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114160" version="1" comment="firefox is earlier than 0:24.5.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:30744"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114141" version="1" comment="firefox is earlier than 0:24.5.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:30786"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113595" version="1" comment="firefox is earlier than 0:24.5.0-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:30909"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113371" version="1" comment="firefox is earlier than 0:24.5.0-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:30529"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115747" version="1" comment="flash-plugin is earlier than 0:11.2.202.378-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:31899"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115295" version="1" comment="flash-plugin is earlier than 0:11.2.202.378-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:31913"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114360" version="1" comment="thunderbird is earlier than 0:24.5.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:30744"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114348" version="1" comment="thunderbird is earlier than 0:24.5.0-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:30909"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114036" version="1" comment="thunderbird is earlier than 0:24.5.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:30786"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113987" version="1" comment="thunderbird is earlier than 0:24.5.0-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:30529"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116162" version="1" comment="thunderbird is earlier than 0:24.7.0-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:32159"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116061" version="1" comment="thunderbird is earlier than 0:24.7.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:31838"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116050" version="1" comment="thunderbird is earlier than 0:24.7.0-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:31874"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116004" version="1" comment="thunderbird is earlier than 0:24.7.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:32072"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114414" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:30470"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114392" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37577"/>
      <state state_ref="oval:org.mitre.oval:ste:31200"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114373" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:30470"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114370" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:31200"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114358" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:30470"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114331" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:31200"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114294" version="1" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14643"/>
      <state state_ref="oval:org.mitre.oval:ste:31200"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114275" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:31200"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114061" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37577"/>
      <state state_ref="oval:org.mitre.oval:ste:30470"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114004" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37509"/>
      <state state_ref="oval:org.mitre.oval:ste:31200"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113923" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:30470"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113837" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:31200"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113811" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:30470"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113772" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:31200"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113443" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37509"/>
      <state state_ref="oval:org.mitre.oval:ste:30470"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114364" version="1" comment="flash-plugin is earlier than 0:11.2.202.359-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:31265"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113835" version="1" comment="flash-plugin is earlier than 0:11.2.202.359-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:31205"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114855" version="1" comment="openssl-devel is earlier than 0:0.9.8e-27.el5_10.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:31056"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114534" version="1" comment="openssl is earlier than 0:0.9.8e-27.el5_10.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:31056"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114504" version="1" comment="openssl-perl is earlier than 0:0.9.8e-27.el5_10.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1005"/>
      <state state_ref="oval:org.mitre.oval:ste:31056"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114303" version="1" comment="struts-manual is earlier than 0:1.2.9-4jpp.8.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38869"/>
      <state state_ref="oval:org.mitre.oval:ste:31174"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114297" version="1" comment="struts is earlier than 0:1.2.9-4jpp.8.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:39111"/>
      <state state_ref="oval:org.mitre.oval:ste:31174"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114193" version="1" comment="struts-webapps-tomcat5 is earlier than 0:1.2.9-4jpp.8.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:39110"/>
      <state state_ref="oval:org.mitre.oval:ste:31174"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113380" version="1" comment="struts-javadoc is earlier than 0:1.2.9-4jpp.8.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38809"/>
      <state state_ref="oval:org.mitre.oval:ste:31174"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114900" version="1" comment="gnutls is earlier than 0:1.4.1-16.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14386"/>
      <state state_ref="oval:org.mitre.oval:ste:31477"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114636" version="1" comment="gnutls-devel is earlier than 0:1.4.1-16.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14558"/>
      <state state_ref="oval:org.mitre.oval:ste:31477"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114627" version="1" comment="gnutls-utils is earlier than 0:1.4.1-16.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15003"/>
      <state state_ref="oval:org.mitre.oval:ste:31477"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115597" version="1" comment="thunderbird is earlier than 0:24.6.0-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:31290"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115511" version="1" comment="thunderbird is earlier than 0:24.6.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:30851"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115386" version="1" comment="thunderbird is earlier than 0:24.6.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:30859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115066" version="1" comment="thunderbird is earlier than 0:24.6.0-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:31822"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114013" version="1" comment="flash-plugin is earlier than 0:11.2.202.356-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:30308"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114008" version="1" comment="flash-plugin is earlier than 0:11.2.202.356-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:31052"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114006" version="1" comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.55-2.4.7.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29032"/>
      <state state_ref="oval:org.mitre.oval:ste:30772"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113927" version="1" comment="java-1.7.0-openjdk is earlier than 1:1.7.0.55-2.4.7.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28860"/>
      <state state_ref="oval:org.mitre.oval:ste:30772"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113915" version="1" comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.55-2.4.7.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29256"/>
      <state state_ref="oval:org.mitre.oval:ste:30772"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113375" version="1" comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.55-2.4.7.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28946"/>
      <state state_ref="oval:org.mitre.oval:ste:30772"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113255" version="1" comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.55-2.4.7.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29000"/>
      <state state_ref="oval:org.mitre.oval:ste:30772"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114302" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-371.8.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:30970"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114292" version="1" comment="kernel-xen is earlier than 0:2.6.18-371.8.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:30970"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114286" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.18-371.8.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:30970"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114204" version="1" comment="kernel-doc is earlier than 0:2.6.18-371.8.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:30970"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114176" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-371.8.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:35004"/>
      <state state_ref="oval:org.mitre.oval:ste:30970"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114139" version="1" comment="kernel-PAE is earlier than 0:2.6.18-371.8.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:30970"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114117" version="1" comment="kernel-headers is earlier than 0:2.6.18-371.8.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38456"/>
      <state state_ref="oval:org.mitre.oval:ste:30970"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114045" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-371.8.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:30970"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113995" version="1" comment="kernel-kdump is earlier than 0:2.6.18-371.8.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37985"/>
      <state state_ref="oval:org.mitre.oval:ste:30970"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113886" version="1" comment="kernel-debug is earlier than 0:2.6.18-371.8.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:30970"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113814" version="1" comment="kernel is earlier than 0:2.6.18-371.8.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:30970"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113719" version="1" comment="kernel-devel is earlier than 0:2.6.18-371.8.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:30970"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114062" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.75-1jpp.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37441"/>
      <state state_ref="oval:org.mitre.oval:ste:31127"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114032" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.75-1jpp.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:31127"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114016" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.75-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:31149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114000" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.75-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:31149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113988" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.75-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:31149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113879" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.75-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:31149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113867" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.75-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:31149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113842" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.75-1jpp.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:31127"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113781" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.75-1jpp.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:31127"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113722" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.75-1jpp.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:31127"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113666" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.75-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37441"/>
      <state state_ref="oval:org.mitre.oval:ste:31149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113239" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.75-1jpp.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:31127"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113476" version="1" comment="httpd-manual is earlier than 0:2.2.3-85.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:30186"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113431" version="1" comment="mod_ssl is earlier than 1:2.2.3-85.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:30631"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113417" version="1" comment="mod_ssl is earlier than 1:2.2.3-85.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:30819"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113392" version="1" comment="httpd-manual is earlier than 0:2.2.3-85.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:30865"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113369" version="1" comment="httpd is earlier than 0:2.2.3-85.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:30865"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113206" version="1" comment="httpd is earlier than 0:2.2.3-85.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:30186"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113200" version="1" comment="httpd-devel is earlier than 0:2.2.3-85.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37757"/>
      <state state_ref="oval:org.mitre.oval:ste:30865"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113061" version="1" comment="httpd-devel is earlier than 0:2.2.3-85.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37757"/>
      <state state_ref="oval:org.mitre.oval:ste:30186"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113976" version="1" comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29158"/>
      <state state_ref="oval:org.mitre.oval:ste:30835"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113955" version="1" comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38181"/>
      <state state_ref="oval:org.mitre.oval:ste:30835"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113949" version="1" comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28861"/>
      <state state_ref="oval:org.mitre.oval:ste:30835"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113941" version="1" comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28836"/>
      <state state_ref="oval:org.mitre.oval:ste:30835"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113900" version="1" comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29211"/>
      <state state_ref="oval:org.mitre.oval:ste:30835"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113802" version="1" comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28861"/>
      <state state_ref="oval:org.mitre.oval:ste:30855"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113785" version="1" comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29158"/>
      <state state_ref="oval:org.mitre.oval:ste:30855"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113657" version="1" comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38120"/>
      <state state_ref="oval:org.mitre.oval:ste:30855"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113612" version="1" comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38120"/>
      <state state_ref="oval:org.mitre.oval:ste:30835"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113525" version="1" comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28836"/>
      <state state_ref="oval:org.mitre.oval:ste:30855"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113277" version="1" comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29211"/>
      <state state_ref="oval:org.mitre.oval:ste:30855"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113074" version="1" comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38181"/>
      <state state_ref="oval:org.mitre.oval:ste:30855"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114381" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38523"/>
      <state state_ref="oval:org.mitre.oval:ste:31295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114372" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:31238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114359" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:31238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114333" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38523"/>
      <state state_ref="oval:org.mitre.oval:ste:31238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114304" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38202"/>
      <state state_ref="oval:org.mitre.oval:ste:31238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114256" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38097"/>
      <state state_ref="oval:org.mitre.oval:ste:31238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114248" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:31295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114217" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:31238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114189" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:31295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114111" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38202"/>
      <state state_ref="oval:org.mitre.oval:ste:31295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114046" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:31238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113950" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:31295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113822" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:31295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113426" version="1" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15027"/>
      <state state_ref="oval:org.mitre.oval:ste:31295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113406" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38097"/>
      <state state_ref="oval:org.mitre.oval:ste:31295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114057" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-5.1.13.3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38018"/>
      <state state_ref="oval:org.mitre.oval:ste:31006"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114041" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-5.1.13.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:30570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114024" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-5.1.13.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:30570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113912" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-5.1.13.3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:31006"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113896" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-5.1.13.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37884"/>
      <state state_ref="oval:org.mitre.oval:ste:30570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113861" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-5.1.13.3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37884"/>
      <state state_ref="oval:org.mitre.oval:ste:31006"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113830" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-5.1.13.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:30570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113683" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-5.1.13.3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:31006"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113650" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-5.1.13.3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:31006"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113056" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-5.1.13.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38018"/>
      <state state_ref="oval:org.mitre.oval:ste:30570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141011" version="1" comment="flash-plugin is earlier than 0:11.2.202.350-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:39351"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113518" version="1" comment="flash-plugin is earlier than 0:11.2.202.350-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:30082"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114858" version="1" comment="mysql55-mysql-bench is earlier than 0:5.5.37-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:34724"/>
      <state state_ref="oval:org.mitre.oval:ste:30672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114777" version="1" comment="mysql55-mysql-server is earlier than 0:5.5.37-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:34983"/>
      <state state_ref="oval:org.mitre.oval:ste:30672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114763" version="1" comment="mysql55-mysql-libs is earlier than 0:5.5.37-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:34878"/>
      <state state_ref="oval:org.mitre.oval:ste:30672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114695" version="1" comment="mysql55-mysql is earlier than 0:5.5.37-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38515"/>
      <state state_ref="oval:org.mitre.oval:ste:30672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114436" version="1" comment="mysql55-mysql-devel is earlier than 0:5.5.37-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38362"/>
      <state state_ref="oval:org.mitre.oval:ste:30672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114420" version="1" comment="mysql55-mysql-test is earlier than 0:5.5.37-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:35130"/>
      <state state_ref="oval:org.mitre.oval:ste:30672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113019" version="1" comment="wireshark is earlier than 0:1.0.15-6.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14711"/>
      <state state_ref="oval:org.mitre.oval:ste:30583"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112967" version="1" comment="wireshark-gnome is earlier than 0:1.0.15-6.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:35757"/>
      <state state_ref="oval:org.mitre.oval:ste:30583"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113365" version="1" comment="xalan-j2-demo is earlier than 0:2.7.0-9.9.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38504"/>
      <state state_ref="oval:org.mitre.oval:ste:29871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113337" version="1" comment="xalan-j2-javadoc is earlier than 0:2.7.0-9.9.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38692"/>
      <state state_ref="oval:org.mitre.oval:ste:29871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113295" version="1" comment="xalan-j2-xsltc is earlier than 0:2.7.0-9.9.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38423"/>
      <state state_ref="oval:org.mitre.oval:ste:29871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113217" version="1" comment="xalan-j2-manual is earlier than 0:2.7.0-9.9.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38224"/>
      <state state_ref="oval:org.mitre.oval:ste:29871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113186" version="1" comment="xalan-j2 is earlier than 0:2.7.0-6jpp.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38637"/>
      <state state_ref="oval:org.mitre.oval:ste:30300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113048" version="1" comment="xalan-j2 is earlier than 0:2.7.0-9.9.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38637"/>
      <state state_ref="oval:org.mitre.oval:ste:29871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112942" version="1" comment="xalan-j2-javadoc is earlier than 0:2.7.0-6jpp.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38692"/>
      <state state_ref="oval:org.mitre.oval:ste:30300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112937" version="1" comment="xalan-j2-demo is earlier than 0:2.7.0-6jpp.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38504"/>
      <state state_ref="oval:org.mitre.oval:ste:30300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112887" version="1" comment="xalan-j2-manual is earlier than 0:2.7.0-6jpp.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38224"/>
      <state state_ref="oval:org.mitre.oval:ste:30300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112612" version="1" comment="xalan-j2-xsltc is earlier than 0:2.7.0-6jpp.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38423"/>
      <state state_ref="oval:org.mitre.oval:ste:30300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112970" version="1" comment="openldap-servers is earlier than 0:2.3.43-27.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14676"/>
      <state state_ref="oval:org.mitre.oval:ste:30232"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112886" version="1" comment="openldap-clients is earlier than 0:2.3.43-27.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13745"/>
      <state state_ref="oval:org.mitre.oval:ste:30232"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112766" version="1" comment="compat-openldap is earlier than 0:2.3.43_2.2.29-27.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14705"/>
      <state state_ref="oval:org.mitre.oval:ste:30268"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112755" version="1" comment="openldap-servers-overlays is earlier than 0:2.3.43-27.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14536"/>
      <state state_ref="oval:org.mitre.oval:ste:30232"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112637" version="1" comment="openldap-servers-sql is earlier than 0:2.3.43-27.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14387"/>
      <state state_ref="oval:org.mitre.oval:ste:30232"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112530" version="1" comment="openldap is earlier than 0:2.3.43-27.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14650"/>
      <state state_ref="oval:org.mitre.oval:ste:30232"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:111982" version="1" comment="openldap-devel is earlier than 0:2.3.43-27.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14680"/>
      <state state_ref="oval:org.mitre.oval:ste:30232"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113902" version="1" comment="firefox is earlier than 0:24.4.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:30281"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113576" version="1" comment="firefox is earlier than 0:24.4.0-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:31105"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113033" version="1" comment="firefox is earlier than 0:24.4.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:30610"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112878" version="1" comment="firefox is earlier than 0:24.4.0-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:30660"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115398" version="1" comment="Red Hat Enterprise 7 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28686"/>
      <state state_ref="oval:org.mitre.oval:ste:31757"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115342" version="1" comment="Oracle Linux 7.x is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:23691"/>
      <state state_ref="oval:org.mitre.oval:ste:31675"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115369" version="1" comment="CentOS Linux 7.x is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:24078"/>
      <state state_ref="oval:org.mitre.oval:ste:31728"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116069" version="1" comment="firefox is earlier than 0:24.6.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:31985"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115672" version="1" comment="xulrunner is earlier than 0:24.6.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:31985"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115498" version="1" comment="firefox is earlier than 0:24.6.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:31614"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115439" version="1" comment="xulrunner is earlier than 0:24.6.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:31614"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115278" version="1" comment="firefox is earlier than 0:24.6.0-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:31290"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115251" version="1" comment="firefox is earlier than 0:24.6.0-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:31822"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115120" version="1" comment="xulrunner-devel is earlier than 0:24.6.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:31614"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114950" version="1" comment="firefox is earlier than 0:24.6.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:30851"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114602" version="1" comment="firefox is earlier than 0:24.6.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:30859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113361" version="1" comment="samba-client is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13861"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113304" version="1" comment="samba3x-client is earlier than 0:3.6.6-0.139.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14854"/>
      <state state_ref="oval:org.mitre.oval:ste:30779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113289" version="1" comment="samba-winbind-devel is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29445"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113272" version="1" comment="samba3x-common is earlier than 0:3.6.6-0.139.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14673"/>
      <state state_ref="oval:org.mitre.oval:ste:30779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113240" version="1" comment="libsmbclient is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37433"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113193" version="1" comment="samba3x is earlier than 0:3.6.6-0.139.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15124"/>
      <state state_ref="oval:org.mitre.oval:ste:30779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113155" version="1" comment="samba3x-swat is earlier than 0:3.6.6-0.139.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15202"/>
      <state state_ref="oval:org.mitre.oval:ste:30779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113128" version="1" comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.139.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15045"/>
      <state state_ref="oval:org.mitre.oval:ste:30779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113084" version="1" comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.139.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15239"/>
      <state state_ref="oval:org.mitre.oval:ste:30779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113058" version="1" comment="samba is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13931"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113037" version="1" comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28660"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112992" version="1" comment="samba3x-winbind is earlier than 0:3.6.6-0.139.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15095"/>
      <state state_ref="oval:org.mitre.oval:ste:30779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112784" version="1" comment="samba-domainjoin-gui is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28867"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112759" version="1" comment="samba-common is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38329"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112720" version="1" comment="samba-winbind-clients is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38277"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112639" version="1" comment="samba-swat is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13707"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112514" version="1" comment="samba3x-doc is earlier than 0:3.6.6-0.139.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14991"/>
      <state state_ref="oval:org.mitre.oval:ste:30779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112481" version="1" comment="samba-doc is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37787"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112379" version="1" comment="libsmbclient-devel is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15335"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112354" version="1" comment="samba-winbind is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29389"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113236" version="1" comment="kernel-doc is earlier than 0:2.6.18-371.6.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:30798"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113211" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.18-371.6.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:30798"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113167" version="1" comment="kernel-PAE is earlier than 0:2.6.18-371.6.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:30798"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113143" version="1" comment="kernel-headers is earlier than 0:2.6.18-371.6.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38456"/>
      <state state_ref="oval:org.mitre.oval:ste:30798"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113138" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-371.6.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:30798"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113114" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-371.6.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:30798"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113100" version="1" comment="kernel-devel is earlier than 0:2.6.18-371.6.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:30798"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113042" version="1" comment="kernel-debug is earlier than 0:2.6.18-371.6.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:30798"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112986" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-371.6.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:35004"/>
      <state state_ref="oval:org.mitre.oval:ste:30798"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112921" version="1" comment="kernel is earlier than 0:2.6.18-371.6.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:30798"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112804" version="1" comment="kernel-xen is earlier than 0:2.6.18-371.6.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:30798"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112592" version="1" comment="kernel-kdump is earlier than 0:2.6.18-371.6.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37985"/>
      <state state_ref="oval:org.mitre.oval:ste:30798"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113028" version="1" comment="sudo is earlier than 0:1.7.2p1-29.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14246"/>
      <state state_ref="oval:org.mitre.oval:ste:30766"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112966" version="1" comment="postgresql-tcl is earlier than 0:8.1.23-10.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14486"/>
      <state state_ref="oval:org.mitre.oval:ste:30204"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112961" version="1" comment="postgresql-contrib is earlier than 0:8.1.23-10.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14293"/>
      <state state_ref="oval:org.mitre.oval:ste:30204"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112894" version="1" comment="postgresql-server is earlier than 0:8.1.23-10.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14158"/>
      <state state_ref="oval:org.mitre.oval:ste:30204"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112732" version="1" comment="postgresql-pl is earlier than 0:8.1.23-10.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14537"/>
      <state state_ref="oval:org.mitre.oval:ste:30204"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112729" version="1" comment="postgresql-python is earlier than 0:8.1.23-10.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14546"/>
      <state state_ref="oval:org.mitre.oval:ste:30204"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112708" version="1" comment="postgresql-docs is earlier than 0:8.1.23-10.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14365"/>
      <state state_ref="oval:org.mitre.oval:ste:30204"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112414" version="1" comment="postgresql-devel is earlier than 0:8.1.23-10.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14290"/>
      <state state_ref="oval:org.mitre.oval:ste:30204"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112385" version="1" comment="postgresql-test is earlier than 0:8.1.23-10.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14367"/>
      <state state_ref="oval:org.mitre.oval:ste:30204"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112345" version="1" comment="postgresql is earlier than 0:8.1.23-10.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14586"/>
      <state state_ref="oval:org.mitre.oval:ste:30204"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112293" version="1" comment="postgresql-libs is earlier than 0:8.1.23-10.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14383"/>
      <state state_ref="oval:org.mitre.oval:ste:30204"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115462" version="1" comment="kernel-debug is earlier than 0:2.6.18-371.9.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:31386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115450" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-371.9.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:31386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115445" version="1" comment="kernel-devel is earlier than 0:2.6.18-371.9.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:31386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115444" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-371.9.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:35004"/>
      <state state_ref="oval:org.mitre.oval:ste:31386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115440" version="1" comment="kernel-headers is earlier than 0:2.6.18-371.9.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38456"/>
      <state state_ref="oval:org.mitre.oval:ste:31386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115436" version="1" comment="kernel-PAE is earlier than 0:2.6.18-371.9.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:31386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115409" version="1" comment="kernel is earlier than 0:2.6.18-371.9.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:31386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115399" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.18-371.9.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:31386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115349" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-371.9.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:31386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115344" version="1" comment="kernel-doc is earlier than 0:2.6.18-371.9.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:31386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115145" version="1" comment="kernel-kdump is earlier than 0:2.6.18-371.9.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37985"/>
      <state state_ref="oval:org.mitre.oval:ste:31386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114597" version="1" comment="kernel-xen is earlier than 0:2.6.18-371.9.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:31386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112885" version="1" comment="libtiff-devel is earlier than 0:3.8.2-19.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14174"/>
      <state state_ref="oval:org.mitre.oval:ste:30528"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112798" version="1" comment="libtiff is earlier than 0:3.8.2-19.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14341"/>
      <state state_ref="oval:org.mitre.oval:ste:30528"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112855" version="1" comment="mysql55-mysql-devel is earlier than 0:5.5.36-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38362"/>
      <state state_ref="oval:org.mitre.oval:ste:30548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112845" version="1" comment="mysql55-mysql-bench is earlier than 0:5.5.36-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38483"/>
      <state state_ref="oval:org.mitre.oval:ste:30548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112751" version="1" comment="mysql55-mysql-test is earlier than 0:5.5.36-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37587"/>
      <state state_ref="oval:org.mitre.oval:ste:30548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112608" version="1" comment="mysql55-mysql is earlier than 0:5.5.36-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38515"/>
      <state state_ref="oval:org.mitre.oval:ste:30548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112568" version="1" comment="mysql55-mysql-libs is earlier than 0:5.5.36-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38421"/>
      <state state_ref="oval:org.mitre.oval:ste:30548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112200" version="1" comment="mysql55-mysql-server is earlier than 0:5.5.36-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37813"/>
      <state state_ref="oval:org.mitre.oval:ste:30548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140799" version="1" comment="flash-plugin is earlier than 0:11.2.202.341-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:39142"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112925" version="1" comment="flash-plugin is earlier than 0:11.2.202.341-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:30194"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112948" version="1" comment="openswan is earlier than 0:2.6.32-27.2.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14994"/>
      <state state_ref="oval:org.mitre.oval:ste:29817"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112726" version="1" comment="openswan-doc is earlier than 0:2.6.32-27.2.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15278"/>
      <state state_ref="oval:org.mitre.oval:ste:29817"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112679" version="1" comment="openswan-doc is earlier than 0:2.6.32-7.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15278"/>
      <state state_ref="oval:org.mitre.oval:ste:30647"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112172" version="1" comment="openswan is earlier than 0:2.6.32-7.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14994"/>
      <state state_ref="oval:org.mitre.oval:ste:30647"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112960" version="1" comment="postgresql-contrib is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14293"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112943" version="1" comment="postgresql84-plpython is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15356"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112909" version="1" comment="postgresql84-contrib is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15329"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112907" version="1" comment="postgresql-pltcl is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29636"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112856" version="1" comment="postgresql-devel is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14290"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112809" version="1" comment="postgresql is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14586"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112803" version="1" comment="postgresql84-python is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15270"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112800" version="1" comment="postgresql84-test is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15176"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112782" version="1" comment="postgresql84-server is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15020"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112749" version="1" comment="postgresql-test is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14367"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112744" version="1" comment="postgresql-docs is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14365"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112717" version="1" comment="postgresql-libs is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14383"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112714" version="1" comment="postgresql84-tcl is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14440"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112698" version="1" comment="postgresql84-devel is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15349"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112684" version="1" comment="postgresql84-docs is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15371"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112658" version="1" comment="postgresql84-libs is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15091"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112596" version="1" comment="postgresql84-plperl is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14866"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112591" version="1" comment="postgresql-server is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14158"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112494" version="1" comment="postgresql-plperl is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29499"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112462" version="1" comment="postgresql-plpython is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29607"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112347" version="1" comment="postgresql84-pltcl is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15092"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112076" version="1" comment="postgresql84 is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15160"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113268" version="1" comment="php-devel is earlier than 0:5.1.6-44.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13492"/>
      <state state_ref="oval:org.mitre.oval:ste:30552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113260" version="1" comment="php-xml is earlier than 0:5.1.6-44.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14560"/>
      <state state_ref="oval:org.mitre.oval:ste:30552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113250" version="1" comment="php-mysql is earlier than 0:5.1.6-44.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14080"/>
      <state state_ref="oval:org.mitre.oval:ste:30552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113198" version="1" comment="php-pdo is earlier than 0:5.1.6-44.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14154"/>
      <state state_ref="oval:org.mitre.oval:ste:30552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113183" version="1" comment="php-xmlrpc is earlier than 0:5.1.6-44.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37980"/>
      <state state_ref="oval:org.mitre.oval:ste:30552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113180" version="1" comment="php-ldap is earlier than 0:5.1.6-44.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14375"/>
      <state state_ref="oval:org.mitre.oval:ste:30552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113163" version="1" comment="php-ncurses is earlier than 0:5.1.6-44.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38058"/>
      <state state_ref="oval:org.mitre.oval:ste:30552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113162" version="1" comment="php-mbstring is earlier than 0:5.1.6-44.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13746"/>
      <state state_ref="oval:org.mitre.oval:ste:30552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113158" version="1" comment="php-pgsql is earlier than 0:5.1.6-44.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38130"/>
      <state state_ref="oval:org.mitre.oval:ste:30552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113142" version="1" comment="php-snmp is earlier than 0:5.1.6-44.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14508"/>
      <state state_ref="oval:org.mitre.oval:ste:30552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113104" version="1" comment="php-gd is earlier than 0:5.1.6-44.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38189"/>
      <state state_ref="oval:org.mitre.oval:ste:30552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113066" version="1" comment="php-soap is earlier than 0:5.1.6-44.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14366"/>
      <state state_ref="oval:org.mitre.oval:ste:30552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113054" version="1" comment="php-odbc is earlier than 0:5.1.6-44.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14183"/>
      <state state_ref="oval:org.mitre.oval:ste:30552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112990" version="1" comment="php-imap is earlier than 0:5.1.6-44.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38478"/>
      <state state_ref="oval:org.mitre.oval:ste:30552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112899" version="1" comment="php-bcmath is earlier than 0:5.1.6-44.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14639"/>
      <state state_ref="oval:org.mitre.oval:ste:30552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112738" version="1" comment="php-cli is earlier than 0:5.1.6-44.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14922"/>
      <state state_ref="oval:org.mitre.oval:ste:30552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112734" version="1" comment="php-common is earlier than 0:5.1.6-44.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14841"/>
      <state state_ref="oval:org.mitre.oval:ste:30552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112715" version="1" comment="php-dba is earlier than 0:5.1.6-44.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14512"/>
      <state state_ref="oval:org.mitre.oval:ste:30552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112287" version="1" comment="php is earlier than 0:5.1.6-44.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14294"/>
      <state state_ref="oval:org.mitre.oval:ste:30552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114639" version="1" comment="openssl097a is earlier than 0:0.9.7a-12.el5_10.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14181"/>
      <state state_ref="oval:org.mitre.oval:ste:31369"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114586" version="1" comment="openssl098e is earlier than 0:0.9.8e-18.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29469"/>
      <state state_ref="oval:org.mitre.oval:ste:31552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113786" version="1" comment="thunderbird is earlier than 0:24.4.0-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:31105"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113625" version="1" comment="thunderbird is earlier than 0:24.4.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:30281"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112930" version="1" comment="thunderbird is earlier than 0:24.4.0-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:30660"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112746" version="1" comment="thunderbird is earlier than 0:24.4.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:30610"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140987" version="1" comment="flash-plugin is earlier than 0:11.2.202.346-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:39305"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112587" version="1" comment="flash-plugin is earlier than 0:11.2.202.346-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:30149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112944" version="1" comment="gnutls is earlier than 0:1.4.1-14.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14386"/>
      <state state_ref="oval:org.mitre.oval:ste:30648"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112703" version="1" comment="gnutls-utils is earlier than 0:1.4.1-14.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15003"/>
      <state state_ref="oval:org.mitre.oval:ste:30648"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112053" version="1" comment="gnutls-devel is earlier than 0:1.4.1-14.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14558"/>
      <state state_ref="oval:org.mitre.oval:ste:30648"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113215" version="1" comment="net-snmp-perl is earlier than 1:5.3.2.2-22.el5_10.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14516"/>
      <state state_ref="oval:org.mitre.oval:ste:30219"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113112" version="1" comment="net-snmp-libs is earlier than 1:5.3.2.2-22.el5_10.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:36003"/>
      <state state_ref="oval:org.mitre.oval:ste:30219"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113082" version="1" comment="net-snmp is earlier than 1:5.3.2.2-22.el5_10.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14390"/>
      <state state_ref="oval:org.mitre.oval:ste:30219"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112801" version="1" comment="net-snmp-devel is earlier than 1:5.3.2.2-22.el5_10.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14339"/>
      <state state_ref="oval:org.mitre.oval:ste:30219"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112340" version="1" comment="net-snmp-utils is earlier than 1:5.3.2.2-22.el5_10.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14287"/>
      <state state_ref="oval:org.mitre.oval:ste:30219"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114375" version="1" comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29376"/>
      <state state_ref="oval:org.mitre.oval:ste:31008"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114263" version="1" comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38317"/>
      <state state_ref="oval:org.mitre.oval:ste:31085"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114196" version="1" comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29364"/>
      <state state_ref="oval:org.mitre.oval:ste:31008"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114182" version="1" comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28520"/>
      <state state_ref="oval:org.mitre.oval:ste:31085"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114180" version="1" comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28974"/>
      <state state_ref="oval:org.mitre.oval:ste:31085"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114142" version="1" comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28974"/>
      <state state_ref="oval:org.mitre.oval:ste:31008"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114105" version="1" comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28520"/>
      <state state_ref="oval:org.mitre.oval:ste:31008"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114099" version="1" comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29064"/>
      <state state_ref="oval:org.mitre.oval:ste:31008"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114034" version="1" comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29364"/>
      <state state_ref="oval:org.mitre.oval:ste:31085"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113910" version="1" comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38317"/>
      <state state_ref="oval:org.mitre.oval:ste:31008"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113637" version="1" comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29376"/>
      <state state_ref="oval:org.mitre.oval:ste:31085"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113583" version="1" comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29064"/>
      <state state_ref="oval:org.mitre.oval:ste:31085"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113242" version="1" comment="samba-common is earlier than 0:3.0.33-3.40.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38329"/>
      <state state_ref="oval:org.mitre.oval:ste:30745"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113212" version="1" comment="samba-client is earlier than 0:3.0.33-3.40.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13861"/>
      <state state_ref="oval:org.mitre.oval:ste:30745"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113154" version="1" comment="samba is earlier than 0:3.0.33-3.40.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13931"/>
      <state state_ref="oval:org.mitre.oval:ste:30745"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113015" version="1" comment="libsmbclient-devel is earlier than 0:3.0.33-3.40.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15335"/>
      <state state_ref="oval:org.mitre.oval:ste:30745"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112977" version="1" comment="libsmbclient is earlier than 0:3.0.33-3.40.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37433"/>
      <state state_ref="oval:org.mitre.oval:ste:30745"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112868" version="1" comment="samba-swat is earlier than 0:3.0.33-3.40.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13707"/>
      <state state_ref="oval:org.mitre.oval:ste:30745"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99593" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:27990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141224" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:39378"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141145" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:39378"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141122" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:39378"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141029" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:39378"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141020" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:39378"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140996" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:39378"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140766" version="1" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15027"/>
      <state state_ref="oval:org.mitre.oval:ste:39378"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140232" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:39378"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100491" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:27990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100435" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:27990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100434" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:27990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100378" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:27990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100365" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:27990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100224" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:27990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113809" version="1" comment="libvirt-client is earlier than 0:0.10.2-29.el6_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29031"/>
      <state state_ref="oval:org.mitre.oval:ste:30795"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113156" version="1" comment="libvirt-python is earlier than 0:0.10.2-29.el6_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15191"/>
      <state state_ref="oval:org.mitre.oval:ste:30795"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100310" version="1" comment="firefox is earlier than 0:24.3.0-2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27701"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100086" version="1" comment="firefox is earlier than 0:24.3.0-2.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27371"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140999" version="1" comment="flash-plugin is earlier than 0:11.2.202.335-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:38649"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100327" version="1" comment="flash-plugin is earlier than 0:11.2.202.335-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:28013"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99955" version="1" comment="kernel-PAE is earlier than 0:2.6.18-371.4.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:27997"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99719" version="1" comment="kernel-doc is earlier than 0:2.6.18-371.4.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:27997"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99541" version="1" comment="kernel is earlier than 0:2.6.18-371.4.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:27997"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100490" version="1" comment="kernel-kdump is earlier than 0:2.6.18-371.4.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:27997"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100477" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-371.4.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:27997"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100460" version="1" comment="kernel-xen is earlier than 0:2.6.18-371.4.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:27997"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100447" version="1" comment="kernel-debug is earlier than 0:2.6.18-371.4.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:27997"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100427" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-371.4.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:27997"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100345" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.18-371.4.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:27997"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100320" version="1" comment="kernel-headers is earlier than 0:2.6.18-371.4.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:27997"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100269" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-371.4.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:27997"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100265" version="1" comment="kernel-devel is earlier than 0:2.6.18-371.4.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:27997"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100501" version="1" comment="piranha is earlier than 0:0.8.4-26.el5_10.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29456"/>
      <state state_ref="oval:org.mitre.oval:ste:28057"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114002" version="1" comment="kmod-kvm-debug is earlier than 0:83-266.el5.centos.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29061"/>
      <state state_ref="oval:org.mitre.oval:ste:30590"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113913" version="1" comment="kvm is earlier than 0:83-266.el5.centos.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15123"/>
      <state state_ref="oval:org.mitre.oval:ste:30590"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113825" version="1" comment="kvm-tools is earlier than 0:83-266.el5.centos.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15126"/>
      <state state_ref="oval:org.mitre.oval:ste:30590"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113808" version="1" comment="kmod-kvm is earlier than 0:83-266.el5.centos.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:35146"/>
      <state state_ref="oval:org.mitre.oval:ste:30590"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113694" version="1" comment="kvm-qemu-img is earlier than 0:83-266.el5.centos.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15183"/>
      <state state_ref="oval:org.mitre.oval:ste:30590"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100594" version="1" comment="kvm is earlier than 0:83-266.el5_10.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15123"/>
      <state state_ref="oval:org.mitre.oval:ste:28116"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100575" version="1" comment="kmod-kvm is earlier than 0:83-266.el5_10.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15240"/>
      <state state_ref="oval:org.mitre.oval:ste:28116"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100519" version="1" comment="kmod-kvm-debug is earlier than 0:83-266.el5_10.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29061"/>
      <state state_ref="oval:org.mitre.oval:ste:28116"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100459" version="1" comment="kvm-qemu-img is earlier than 0:83-266.el5_10.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15183"/>
      <state state_ref="oval:org.mitre.oval:ste:28116"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100105" version="1" comment="kvm-tools is earlier than 0:83-266.el5_10.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15126"/>
      <state state_ref="oval:org.mitre.oval:ste:28116"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99514" version="1" comment="flash-plugin is earlier than 0:11.2.202.336-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:27714"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141146" version="1" comment="flash-plugin is earlier than 0:11.2.202.336-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:39199"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99642" version="1" comment="libpng-devel is earlier than 2:1.2.10-7.1.el5_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:951"/>
      <state state_ref="oval:org.mitre.oval:ste:27621"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99428" version="1" comment="libpng is earlier than 2:1.2.10-7.1.el5_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:952"/>
      <state state_ref="oval:org.mitre.oval:ste:27621"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99626" version="1" comment="openldap-servers-overlays is earlier than 0:2.3.43-12.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14536"/>
      <state state_ref="oval:org.mitre.oval:ste:27384"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99620" version="1" comment="compat-openldap is earlier than 0:2.3.43_2.2.29-12.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14705"/>
      <state state_ref="oval:org.mitre.oval:ste:27759"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99614" version="1" comment="openldap-devel is earlier than 0:2.3.43-12.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14680"/>
      <state state_ref="oval:org.mitre.oval:ste:27384"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99598" version="1" comment="openldap-clients is earlier than 0:2.3.43-12.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13745"/>
      <state state_ref="oval:org.mitre.oval:ste:27384"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99479" version="1" comment="openldap-servers-sql is earlier than 0:2.3.43-12.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14387"/>
      <state state_ref="oval:org.mitre.oval:ste:27384"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99477" version="1" comment="openldap-servers is earlier than 0:2.3.43-12.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14676"/>
      <state state_ref="oval:org.mitre.oval:ste:27384"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99292" version="1" comment="openldap is earlier than 0:2.3.43-12.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14650"/>
      <state state_ref="oval:org.mitre.oval:ste:27384"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99404" version="1" comment="freetype is earlier than 0:2.2.1-28.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14103"/>
      <state state_ref="oval:org.mitre.oval:ste:26838"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99397" version="1" comment="freetype-demos is earlier than 0:2.2.1-28.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14713"/>
      <state state_ref="oval:org.mitre.oval:ste:26838"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98803" version="1" comment="freetype-devel is earlier than 0:2.2.1-28.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14561"/>
      <state state_ref="oval:org.mitre.oval:ste:26838"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99535" version="1" comment="flash-plugin is earlier than 0:10.1.82.76-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:27697"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99701" version="1" comment="xulrunner is earlier than 0:1.9.2.11-4.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27827"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98944" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.11-4.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27827"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99784" version="1" comment="xulrunner is earlier than 0:1.9.2.11-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27643"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99744" version="1" comment="nss is earlier than 0:3.12.8-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:26989"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99712" version="1" comment="nss-devel is earlier than 0:3.12.8-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:26989"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99705" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.11-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27643"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99646" version="1" comment="nss-pkcs11-devel is earlier than 0:3.12.8-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:26989"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99517" version="1" comment="nss-tools is earlier than 0:3.12.8-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:26989"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99096" version="1" comment="firefox is earlier than 0:3.6.11-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27545"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99434" version="1" comment="kdegraphics is earlier than 7:3.5.4-17.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14241"/>
      <state state_ref="oval:org.mitre.oval:ste:27809"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99183" version="1" comment="kdegraphics-devel is earlier than 7:3.5.4-17.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14596"/>
      <state state_ref="oval:org.mitre.oval:ste:27809"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99986" version="1" comment="kmod-kvm is earlier than 0:83-164.el5_5.25" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15240"/>
      <state state_ref="oval:org.mitre.oval:ste:27586"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99968" version="1" comment="kvm-qemu-img is earlier than 0:83-164.el5_5.25" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15183"/>
      <state state_ref="oval:org.mitre.oval:ste:27586"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99878" version="1" comment="kvm-tools is earlier than 0:83-164.el5_5.25" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15126"/>
      <state state_ref="oval:org.mitre.oval:ste:27586"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99776" version="1" comment="kvm is earlier than 0:83-164.el5_5.25" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15123"/>
      <state state_ref="oval:org.mitre.oval:ste:27586"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99820" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.2-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:27471"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99673" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.2-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:27471"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99553" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.2-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:27471"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99510" version="1" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.2-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14643"/>
      <state state_ref="oval:org.mitre.oval:ste:27471"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99494" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.2-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:27471"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99473" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.2-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:27471"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99342" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.2-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:27471"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99210" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.2-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:27471"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99435" version="1" comment="perl-suidperl is earlier than 4:5.8.8-32.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13815"/>
      <state state_ref="oval:org.mitre.oval:ste:27743"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99315" version="1" comment="perl is earlier than 4:5.8.8-32.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14460"/>
      <state state_ref="oval:org.mitre.oval:ste:27743"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99616" version="1" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.5-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14163"/>
      <state state_ref="oval:org.mitre.oval:ste:27254"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99590" version="1" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.5-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14829"/>
      <state state_ref="oval:org.mitre.oval:ste:27254"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99573" version="1" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.5-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14312"/>
      <state state_ref="oval:org.mitre.oval:ste:27254"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99530" version="1" comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.5-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14781"/>
      <state state_ref="oval:org.mitre.oval:ste:27254"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99490" version="1" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.5-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14703"/>
      <state state_ref="oval:org.mitre.oval:ste:27254"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99457" version="1" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.5-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14755"/>
      <state state_ref="oval:org.mitre.oval:ste:27254"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99321" version="1" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.5-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14837"/>
      <state state_ref="oval:org.mitre.oval:ste:27254"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99791" version="1" comment="thunderbird is earlier than 0:2.0.0.24-10.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:27652"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99669" version="1" comment="nss-devel is earlier than 0:3.12.7-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:27581"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99666" version="1" comment="nspr-devel is earlier than 0:4.8.6-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15145"/>
      <state state_ref="oval:org.mitre.oval:ste:27556"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99649" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.9-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27733"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99633" version="1" comment="firefox is earlier than 0:3.6.9-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27608"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99623" version="1" comment="xulrunner is earlier than 0:1.9.2.9-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27733"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99550" version="1" comment="nss is earlier than 0:3.12.7-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:27581"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99498" version="1" comment="nss-pkcs11-devel is earlier than 0:3.12.7-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:27581"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99345" version="1" comment="nss-tools is earlier than 0:3.12.7-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:27581"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98911" version="1" comment="nspr is earlier than 0:4.8.6-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14745"/>
      <state state_ref="oval:org.mitre.oval:ste:27556"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99697" version="1" comment="acroread is earlier than 0:9.3.4-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14858"/>
      <state state_ref="oval:org.mitre.oval:ste:27781"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99093" version="1" comment="acroread-plugin is earlier than 0:9.3.4-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14489"/>
      <state state_ref="oval:org.mitre.oval:ste:27781"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99667" version="1" comment="xulrunner is earlier than 0:1.9.2.7-3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27280"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99558" version="1" comment="firefox is earlier than 0:3.6.7-3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27744"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99443" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.7-3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27280"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99963" version="1" comment="apr-util-ldap is earlier than 0:1.3.9-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29939"/>
      <state state_ref="oval:org.mitre.oval:ste:27599"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99933" version="1" comment="apr-util is earlier than 0:1.3.9-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14992"/>
      <state state_ref="oval:org.mitre.oval:ste:27599"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99866" version="1" comment="apr-util-docs is earlier than 0:1.2.7-11.el5_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15199"/>
      <state state_ref="oval:org.mitre.oval:ste:27750"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99848" version="1" comment="apr-util-mysql is earlier than 0:1.3.9-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29834"/>
      <state state_ref="oval:org.mitre.oval:ste:27599"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99823" version="1" comment="apr-util-mysql is earlier than 0:1.2.7-11.el5_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29834"/>
      <state state_ref="oval:org.mitre.oval:ste:27750"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99298" version="1" comment="apr-util-devel is earlier than 0:1.2.7-11.el5_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15236"/>
      <state state_ref="oval:org.mitre.oval:ste:27750"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99237" version="1" comment="apr-util-pgsql is earlier than 0:1.3.9-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30282"/>
      <state state_ref="oval:org.mitre.oval:ste:27599"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100112" version="1" comment="apr-util-odbc is earlier than 0:1.3.9-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30351"/>
      <state state_ref="oval:org.mitre.oval:ste:27599"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100104" version="1" comment="apr-util-sqlite is earlier than 0:1.3.9-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30161"/>
      <state state_ref="oval:org.mitre.oval:ste:27599"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100092" version="1" comment="apr-util-devel is earlier than 0:1.3.9-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15236"/>
      <state state_ref="oval:org.mitre.oval:ste:27599"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100054" version="1" comment="apr-util is earlier than 0:1.2.7-11.el5_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14992"/>
      <state state_ref="oval:org.mitre.oval:ste:27750"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99671" version="1" comment="avahi-tools is earlier than 0:0.6.16-9.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15172"/>
      <state state_ref="oval:org.mitre.oval:ste:27725"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99658" version="1" comment="avahi-compat-howl-devel is earlier than 0:0.6.16-9.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14459"/>
      <state state_ref="oval:org.mitre.oval:ste:27725"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99654" version="1" comment="avahi-compat-libdns_sd-devel is earlier than 0:0.6.16-9.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14977"/>
      <state state_ref="oval:org.mitre.oval:ste:27725"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99639" version="1" comment="avahi-glib-devel is earlier than 0:0.6.16-9.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14417"/>
      <state state_ref="oval:org.mitre.oval:ste:27725"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99578" version="1" comment="avahi-glib is earlier than 0:0.6.16-9.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14590"/>
      <state state_ref="oval:org.mitre.oval:ste:27725"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99566" version="1" comment="avahi-compat-libdns_sd is earlier than 0:0.6.16-9.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14856"/>
      <state state_ref="oval:org.mitre.oval:ste:27725"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99533" version="1" comment="avahi is earlier than 0:0.6.16-9.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14891"/>
      <state state_ref="oval:org.mitre.oval:ste:27725"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99341" version="1" comment="avahi-compat-howl is earlier than 0:0.6.16-9.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14998"/>
      <state state_ref="oval:org.mitre.oval:ste:27725"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99179" version="1" comment="avahi-qt3 is earlier than 0:0.6.16-9.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14742"/>
      <state state_ref="oval:org.mitre.oval:ste:27725"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99142" version="1" comment="avahi-devel is earlier than 0:0.6.16-9.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14981"/>
      <state state_ref="oval:org.mitre.oval:ste:27725"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99072" version="1" comment="avahi-qt3-devel is earlier than 0:0.6.16-9.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14570"/>
      <state state_ref="oval:org.mitre.oval:ste:27725"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99527" version="1" comment="xulrunner is earlier than 0:1.9.2.7-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27119"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99447" version="1" comment="firefox is earlier than 0:3.6.7-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27567"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99114" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.7-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27119"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99805" version="1" comment="mysql-test is earlier than 0:5.0.77-4.el5_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14941"/>
      <state state_ref="oval:org.mitre.oval:ste:27483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99715" version="1" comment="mysql-devel is earlier than 0:5.0.77-4.el5_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14481"/>
      <state state_ref="oval:org.mitre.oval:ste:27483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99303" version="1" comment="mysql-bench is earlier than 0:5.0.77-4.el5_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14400"/>
      <state state_ref="oval:org.mitre.oval:ste:27483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99302" version="1" comment="mysql is earlier than 0:5.0.77-4.el5_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14355"/>
      <state state_ref="oval:org.mitre.oval:ste:27483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98870" version="1" comment="mysql-server is earlier than 0:5.0.77-4.el5_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14342"/>
      <state state_ref="oval:org.mitre.oval:ste:27483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99648" version="1" comment="acroread is earlier than 0:9.4.0-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14858"/>
      <state state_ref="oval:org.mitre.oval:ste:27609"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99506" version="1" comment="acroread-plugin is earlier than 0:9.4.0-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14489"/>
      <state state_ref="oval:org.mitre.oval:ste:27609"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99636" version="1" comment="perl-Archive-Tar is earlier than 1:1.39.1-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15210"/>
      <state state_ref="oval:org.mitre.oval:ste:27671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99824" version="1" comment="flash-plugin is earlier than 0:10.1.102.64-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:27856"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99534" version="1" comment="thunderbird is earlier than 0:2.0.0.24-9.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:27788"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99988" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:27863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99977" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:27402"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99913" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:27402"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99841" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:27863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99840" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:27402"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99711" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:27863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99645" version="1" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.0-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15027"/>
      <state state_ref="oval:org.mitre.oval:ste:27863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99638" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:27402"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99549" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:27402"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99487" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:27402"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100131" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:27402"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100048" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:27863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100039" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:27863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100029" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:27863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100028" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:27863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99691" version="1" comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_5.14" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14966"/>
      <state state_ref="oval:org.mitre.oval:ste:27388"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99539" version="1" comment="poppler is earlier than 0:0.5.4-4.4.el5_5.14" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14394"/>
      <state state_ref="oval:org.mitre.oval:ste:27388"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98991" version="1" comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_5.14" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14640"/>
      <state state_ref="oval:org.mitre.oval:ste:27388"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99491" version="1" comment="cups is earlier than 1:1.3.7-18.el5_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14199"/>
      <state state_ref="oval:org.mitre.oval:ste:27317"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99332" version="1" comment="cups-lpd is earlier than 1:1.3.7-18.el5_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14688"/>
      <state state_ref="oval:org.mitre.oval:ste:27317"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99115" version="1" comment="cups-devel is earlier than 1:1.3.7-18.el5_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14076"/>
      <state state_ref="oval:org.mitre.oval:ste:27317"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98630" version="1" comment="cups-libs is earlier than 1:1.3.7-18.el5_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14195"/>
      <state state_ref="oval:org.mitre.oval:ste:27317"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99745" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-194.11.4.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:27710"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99732" version="1" comment="kernel-doc is earlier than 0:2.6.18-194.11.4.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:27710"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99730" version="1" comment="kernel is earlier than 0:2.6.18-194.11.4.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:27710"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99670" version="1" comment="kernel-debug is earlier than 0:2.6.18-194.11.4.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:27710"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99634" version="1" comment="kernel-kdump is earlier than 0:2.6.18-194.11.4.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:27710"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99617" version="1" comment="kernel-headers is earlier than 0:2.6.18-194.11.4.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:27710"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99563" version="1" comment="kernel-devel is earlier than 0:2.6.18-194.11.4.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:27710"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99450" version="1" comment="kernel-PAE is earlier than 0:2.6.18-194.11.4.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:27710"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99390" version="1" comment="kernel-xen is earlier than 0:2.6.18-194.11.4.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:27710"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99297" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-194.11.4.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:27710"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99060" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.18-194.11.4.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:27710"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98800" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-194.11.4.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:27710"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99194" version="1" comment="gnupg2 is earlier than 0:2.0.10-3.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29398"/>
      <state state_ref="oval:org.mitre.oval:ste:27249"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99735" version="1" comment="quagga-devel is earlier than 0:0.98.6-5.el5_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14340"/>
      <state state_ref="oval:org.mitre.oval:ste:27756"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99525" version="1" comment="quagga is earlier than 0:0.98.6-5.el5_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14268"/>
      <state state_ref="oval:org.mitre.oval:ste:27756"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99470" version="1" comment="quagga-contrib is earlier than 0:0.98.6-5.el5_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14111"/>
      <state state_ref="oval:org.mitre.oval:ste:27756"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99827" version="1" comment="bind-utils is earlier than 30:9.3.6-4.P1.el5_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:27646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99674" version="1" comment="bind-libbind-devel is earlier than 30:9.3.6-4.P1.el5_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14729"/>
      <state state_ref="oval:org.mitre.oval:ste:27646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99604" version="1" comment="caching-nameserver is earlier than 30:9.3.6-4.P1.el5_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14701"/>
      <state state_ref="oval:org.mitre.oval:ste:27646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99481" version="1" comment="bind-chroot is earlier than 30:9.3.6-4.P1.el5_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:27646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99440" version="1" comment="bind-libs is earlier than 30:9.3.6-4.P1.el5_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:27646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99433" version="1" comment="bind is earlier than 30:9.3.6-4.P1.el5_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:27646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100129" version="1" comment="bind-devel is earlier than 30:9.3.6-4.P1.el5_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:27646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100050" version="1" comment="bind-sdb is earlier than 30:9.3.6-4.P1.el5_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:27646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99949" version="1" comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29376"/>
      <state state_ref="oval:org.mitre.oval:ste:27888"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141081" version="1" comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29107"/>
      <state state_ref="oval:org.mitre.oval:ste:39547"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141057" version="1" comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29064"/>
      <state state_ref="oval:org.mitre.oval:ste:39547"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141052" version="1" comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29376"/>
      <state state_ref="oval:org.mitre.oval:ste:39547"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141036" version="1" comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29364"/>
      <state state_ref="oval:org.mitre.oval:ste:39547"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140896" version="1" comment="java-1.7.0-ibm is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28520"/>
      <state state_ref="oval:org.mitre.oval:ste:39547"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140881" version="1" comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28974"/>
      <state state_ref="oval:org.mitre.oval:ste:39547"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100483" version="1" comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28974"/>
      <state state_ref="oval:org.mitre.oval:ste:27888"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100425" version="1" comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29364"/>
      <state state_ref="oval:org.mitre.oval:ste:27888"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100370" version="1" comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29107"/>
      <state state_ref="oval:org.mitre.oval:ste:27888"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100295" version="1" comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29064"/>
      <state state_ref="oval:org.mitre.oval:ste:27888"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100082" version="1" comment="java-1.7.0-ibm is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28520"/>
      <state state_ref="oval:org.mitre.oval:ste:27888"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98806" version="1" comment="qspice-client is earlier than 0:0.3.0-4.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30114"/>
      <state state_ref="oval:org.mitre.oval:ste:27590"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99997" version="1" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.7-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14837"/>
      <state state_ref="oval:org.mitre.oval:ste:27859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99812" version="1" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.7-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14829"/>
      <state state_ref="oval:org.mitre.oval:ste:27859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99789" version="1" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.7-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14755"/>
      <state state_ref="oval:org.mitre.oval:ste:27859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99714" version="1" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.7-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14703"/>
      <state state_ref="oval:org.mitre.oval:ste:27859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99458" version="1" comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.7-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14781"/>
      <state state_ref="oval:org.mitre.oval:ste:27859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100097" version="1" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.7-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14163"/>
      <state state_ref="oval:org.mitre.oval:ste:27859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100088" version="1" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.7-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14312"/>
      <state state_ref="oval:org.mitre.oval:ste:27859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99941" version="1" comment="freetype-devel is earlier than 0:2.3.11-6.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14561"/>
      <state state_ref="oval:org.mitre.oval:ste:27009"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99899" version="1" comment="freetype-demos is earlier than 0:2.3.11-6.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14713"/>
      <state state_ref="oval:org.mitre.oval:ste:27009"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99767" version="1" comment="freetype is earlier than 0:2.2.1-28.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14103"/>
      <state state_ref="oval:org.mitre.oval:ste:27485"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99759" version="1" comment="freetype-demos is earlier than 0:2.2.1-28.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14713"/>
      <state state_ref="oval:org.mitre.oval:ste:27485"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99736" version="1" comment="freetype is earlier than 0:2.3.11-6.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14103"/>
      <state state_ref="oval:org.mitre.oval:ste:27009"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100020" version="1" comment="freetype-devel is earlier than 0:2.2.1-28.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14561"/>
      <state state_ref="oval:org.mitre.oval:ste:27485"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99765" version="1" comment="kernel-kdump is earlier than 0:2.6.18-194.17.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:27783"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99751" version="1" comment="kernel-doc is earlier than 0:2.6.18-194.17.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:27783"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99722" version="1" comment="kernel-debug is earlier than 0:2.6.18-194.17.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:27783"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99703" version="1" comment="kernel-PAE is earlier than 0:2.6.18-194.17.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:27783"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99695" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-194.17.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:27783"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99515" version="1" comment="kernel-devel is earlier than 0:2.6.18-194.17.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:27783"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99472" version="1" comment="kernel is earlier than 0:2.6.18-194.17.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:27783"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99425" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.18-194.17.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:27783"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99126" version="1" comment="kernel-xen is earlier than 0:2.6.18-194.17.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:27783"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98897" version="1" comment="kernel-headers is earlier than 0:2.6.18-194.17.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:27783"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98871" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-194.17.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:27783"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98776" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-194.17.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:27783"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99809" version="1" comment="libpurple-perl is earlier than 0:2.6.6-5.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:27628"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99787" version="1" comment="pidgin is earlier than 0:2.6.6-5.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:27628"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99782" version="1" comment="finch is earlier than 0:2.6.6-5.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:27628"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99778" version="1" comment="pidgin-perl is earlier than 0:2.6.6-5.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:27628"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99661" version="1" comment="pidgin-devel is earlier than 0:2.6.6-5.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:27628"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99521" version="1" comment="libpurple is earlier than 0:2.6.6-5.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:27628"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99504" version="1" comment="libpurple-devel is earlier than 0:2.6.6-5.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:27628"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99503" version="1" comment="finch-devel is earlier than 0:2.6.6-5.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:27628"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98903" version="1" comment="libpurple-tcl is earlier than 0:2.6.6-5.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:27628"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99982" version="1" comment="acroread-plugin is earlier than 0:9.4.1-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14489"/>
      <state state_ref="oval:org.mitre.oval:ste:27658"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99895" version="1" comment="acroread is earlier than 0:9.4.1-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14858"/>
      <state state_ref="oval:org.mitre.oval:ste:27658"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99687" version="1" comment="acroread is earlier than 0:9.4.1-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14858"/>
      <state state_ref="oval:org.mitre.oval:ste:26871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100085" version="1" comment="acroread-plugin is earlier than 0:9.4.1-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14489"/>
      <state state_ref="oval:org.mitre.oval:ste:26871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99664" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.8.1-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:27713"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99635" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.8.1-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:27713"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99595" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.8.1-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:27713"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99544" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.8.1-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:27713"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99520" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.8.1-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:27713"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99316" version="1" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.8.1-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15027"/>
      <state state_ref="oval:org.mitre.oval:ste:27713"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99313" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.8.1-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:27713"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99260" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.8.1-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:27713"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99643" version="1" comment="pcsc-lite-doc is earlier than 0:1.4.4-4.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29308"/>
      <state state_ref="oval:org.mitre.oval:ste:27310"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99618" version="1" comment="pcsc-lite is earlier than 0:1.4.4-4.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28933"/>
      <state state_ref="oval:org.mitre.oval:ste:27310"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99387" version="1" comment="pcsc-lite-devel is earlier than 0:1.4.4-4.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28336"/>
      <state state_ref="oval:org.mitre.oval:ste:27310"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99319" version="1" comment="pcsc-lite-libs is earlier than 0:1.4.4-4.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28571"/>
      <state state_ref="oval:org.mitre.oval:ste:27310"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99421" version="1" comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14182"/>
      <state state_ref="oval:org.mitre.oval:ste:27698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99392" version="1" comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14502"/>
      <state state_ref="oval:org.mitre.oval:ste:27698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99367" version="1" comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13878"/>
      <state state_ref="oval:org.mitre.oval:ste:27698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99284" version="1" comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14554"/>
      <state state_ref="oval:org.mitre.oval:ste:27698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99270" version="1" comment="tetex is earlier than 0:3.0-33.8.el5_5.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14329"/>
      <state state_ref="oval:org.mitre.oval:ste:27698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98820" version="1" comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14389"/>
      <state state_ref="oval:org.mitre.oval:ste:27698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98819" version="1" comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14207"/>
      <state state_ref="oval:org.mitre.oval:ste:27698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99916" version="1" comment="krb5-devel is earlier than 0:1.6.1-36.el5_5.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14100"/>
      <state state_ref="oval:org.mitre.oval:ste:27732"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99128" version="1" comment="krb5 is earlier than 0:1.6.1-36.el5_5.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14120"/>
      <state state_ref="oval:org.mitre.oval:ste:27732"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100113" version="1" comment="krb5-server is earlier than 0:1.6.1-36.el5_5.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14452"/>
      <state state_ref="oval:org.mitre.oval:ste:27732"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100100" version="1" comment="krb5-libs is earlier than 0:1.6.1-36.el5_5.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14395"/>
      <state state_ref="oval:org.mitre.oval:ste:27732"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100066" version="1" comment="krb5-workstation is earlier than 0:1.6.1-36.el5_5.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14279"/>
      <state state_ref="oval:org.mitre.oval:ste:27732"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99579" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.11.2-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:26807"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99508" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.11.2-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:26807"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99507" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.11.2-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:26807"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99422" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.11.2-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:26807"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99410" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.11.2-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:26807"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99376" version="1" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.11.2-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14643"/>
      <state state_ref="oval:org.mitre.oval:ste:26807"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99193" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.11.2-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:26807"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98604" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.11.2-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:26807"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99343" version="1" comment="acroread is earlier than 0:9.3.3-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14858"/>
      <state state_ref="oval:org.mitre.oval:ste:26828"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98769" version="1" comment="acroread-plugin is earlier than 0:9.3.3-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14489"/>
      <state state_ref="oval:org.mitre.oval:ste:26828"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98887" version="1" comment="thunderbird is earlier than 0:2.0.0.24-6.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:27404"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99665" version="1" comment="lvm2-cluster is earlier than 0:2.02.56-7.el5_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30160"/>
      <state state_ref="oval:org.mitre.oval:ste:26915"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99423" version="1" comment="sudo is earlier than 0:1.7.2p1-6.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14246"/>
      <state state_ref="oval:org.mitre.oval:ste:27676"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99777" version="1" comment="postgresql84-libs is earlier than 0:8.4.5-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15091"/>
      <state state_ref="oval:org.mitre.oval:ste:27806"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99754" version="1" comment="postgresql-test is earlier than 0:8.1.22-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14367"/>
      <state state_ref="oval:org.mitre.oval:ste:27753"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99749" version="1" comment="postgresql-tcl is earlier than 0:8.1.22-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14486"/>
      <state state_ref="oval:org.mitre.oval:ste:27753"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99721" version="1" comment="postgresql84-pltcl is earlier than 0:8.4.5-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15092"/>
      <state state_ref="oval:org.mitre.oval:ste:27806"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99713" version="1" comment="postgresql84-test is earlier than 0:8.4.5-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15176"/>
      <state state_ref="oval:org.mitre.oval:ste:27806"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99640" version="1" comment="postgresql84 is earlier than 0:8.4.5-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15160"/>
      <state state_ref="oval:org.mitre.oval:ste:27806"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99605" version="1" comment="postgresql84-plperl is earlier than 0:8.4.5-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14866"/>
      <state state_ref="oval:org.mitre.oval:ste:27806"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99603" version="1" comment="postgresql84-tcl is earlier than 0:8.4.5-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14440"/>
      <state state_ref="oval:org.mitre.oval:ste:27806"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99576" version="1" comment="postgresql84-docs is earlier than 0:8.4.5-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15371"/>
      <state state_ref="oval:org.mitre.oval:ste:27806"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99565" version="1" comment="postgresql84-python is earlier than 0:8.4.5-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15270"/>
      <state state_ref="oval:org.mitre.oval:ste:27806"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99564" version="1" comment="postgresql-server is earlier than 0:8.1.22-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14158"/>
      <state state_ref="oval:org.mitre.oval:ste:27753"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99552" version="1" comment="postgresql-pl is earlier than 0:8.1.22-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14537"/>
      <state state_ref="oval:org.mitre.oval:ste:27753"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99528" version="1" comment="postgresql84-contrib is earlier than 0:8.4.5-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15329"/>
      <state state_ref="oval:org.mitre.oval:ste:27806"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99516" version="1" comment="postgresql84-devel is earlier than 0:8.4.5-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15349"/>
      <state state_ref="oval:org.mitre.oval:ste:27806"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99512" version="1" comment="postgresql-contrib is earlier than 0:8.1.22-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14293"/>
      <state state_ref="oval:org.mitre.oval:ste:27753"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99489" version="1" comment="postgresql84-server is earlier than 0:8.4.5-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15020"/>
      <state state_ref="oval:org.mitre.oval:ste:27806"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99389" version="1" comment="postgresql-libs is earlier than 0:8.1.22-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14383"/>
      <state state_ref="oval:org.mitre.oval:ste:27753"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99317" version="1" comment="postgresql is earlier than 0:8.1.22-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14586"/>
      <state state_ref="oval:org.mitre.oval:ste:27753"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99174" version="1" comment="postgresql-python is earlier than 0:8.1.22-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14546"/>
      <state state_ref="oval:org.mitre.oval:ste:27753"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99171" version="1" comment="postgresql-docs is earlier than 0:8.1.22-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14365"/>
      <state state_ref="oval:org.mitre.oval:ste:27753"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98927" version="1" comment="postgresql-devel is earlier than 0:8.1.22-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14290"/>
      <state state_ref="oval:org.mitre.oval:ste:27753"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98805" version="1" comment="postgresql84-plpython is earlier than 0:8.4.5-1.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15356"/>
      <state state_ref="oval:org.mitre.oval:ste:27806"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99844" version="1" comment="cups-lpd is earlier than 1:1.3.7-18.el5_5.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14688"/>
      <state state_ref="oval:org.mitre.oval:ste:27857"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99810" version="1" comment="cups-devel is earlier than 1:1.3.7-18.el5_5.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14076"/>
      <state state_ref="oval:org.mitre.oval:ste:27857"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99704" version="1" comment="cups-libs is earlier than 1:1.3.7-18.el5_5.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14195"/>
      <state state_ref="oval:org.mitre.oval:ste:27857"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99582" version="1" comment="cups is earlier than 1:1.3.7-18.el5_5.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14199"/>
      <state state_ref="oval:org.mitre.oval:ste:27857"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99720" version="1" comment="samba-client is earlier than 0:3.0.33-3.29.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13861"/>
      <state state_ref="oval:org.mitre.oval:ste:27389"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99652" version="1" comment="samba-swat is earlier than 0:3.0.33-3.29.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13707"/>
      <state state_ref="oval:org.mitre.oval:ste:27389"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99647" version="1" comment="libsmbclient is earlier than 0:3.0.33-3.29.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15389"/>
      <state state_ref="oval:org.mitre.oval:ste:27389"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99459" version="1" comment="samba is earlier than 0:3.0.33-3.29.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13931"/>
      <state state_ref="oval:org.mitre.oval:ste:27389"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99095" version="1" comment="samba-common is earlier than 0:3.0.33-3.29.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14032"/>
      <state state_ref="oval:org.mitre.oval:ste:27389"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98866" version="1" comment="libsmbclient-devel is earlier than 0:3.0.33-3.29.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15335"/>
      <state state_ref="oval:org.mitre.oval:ste:27389"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99622" version="1" comment="freetype-devel is earlier than 0:2.2.1-25.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14561"/>
      <state state_ref="oval:org.mitre.oval:ste:27773"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99596" version="1" comment="freetype is earlier than 0:2.2.1-25.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14103"/>
      <state state_ref="oval:org.mitre.oval:ste:27773"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99589" version="1" comment="freetype-demos is earlier than 0:2.2.1-25.el5_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14713"/>
      <state state_ref="oval:org.mitre.oval:ste:27773"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99175" version="1" comment="kvm-qemu-img is earlier than 0:83-164.el5_5.30" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15183"/>
      <state state_ref="oval:org.mitre.oval:ste:27635"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100169" version="1" comment="kvm-tools is earlier than 0:83-164.el5_5.30" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15126"/>
      <state state_ref="oval:org.mitre.oval:ste:27635"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100015" version="1" comment="kvm is earlier than 0:83-164.el5_5.30" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15123"/>
      <state state_ref="oval:org.mitre.oval:ste:27635"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100004" version="1" comment="kmod-kvm is earlier than 0:83-164.el5_5.30" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15240"/>
      <state state_ref="oval:org.mitre.oval:ste:27635"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99681" version="1" comment="ImageMagick-c++ is earlier than 0:6.2.8.0-4.el5_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13475"/>
      <state state_ref="oval:org.mitre.oval:ste:26872"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99612" version="1" comment="ImageMagick is earlier than 0:6.2.8.0-4.el5_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13854"/>
      <state state_ref="oval:org.mitre.oval:ste:26872"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99493" version="1" comment="ImageMagick-c++-devel is earlier than 0:6.2.8.0-4.el5_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14240"/>
      <state state_ref="oval:org.mitre.oval:ste:26872"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99476" version="1" comment="ImageMagick-devel is earlier than 0:6.2.8.0-4.el5_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13484"/>
      <state state_ref="oval:org.mitre.oval:ste:26872"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99278" version="1" comment="ImageMagick-perl is earlier than 0:6.2.8.0-4.el5_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14270"/>
      <state state_ref="oval:org.mitre.oval:ste:26872"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99353" version="1" comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.76.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14873"/>
      <state state_ref="oval:org.mitre.oval:ste:26769"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99286" version="1" comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.76.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14709"/>
      <state state_ref="oval:org.mitre.oval:ste:26769"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99092" version="1" comment="xorg-x11-server is earlier than 0:1.1.1-48.76.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14418"/>
      <state state_ref="oval:org.mitre.oval:ste:26769"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99056" version="1" comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.76.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14667"/>
      <state state_ref="oval:org.mitre.oval:ste:26769"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99043" version="1" comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.76.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14353"/>
      <state state_ref="oval:org.mitre.oval:ste:26769"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98989" version="1" comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.76.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14653"/>
      <state state_ref="oval:org.mitre.oval:ste:26769"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98914" version="1" comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.76.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14794"/>
      <state state_ref="oval:org.mitre.oval:ste:26769"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98686" version="1" comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.76.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14842"/>
      <state state_ref="oval:org.mitre.oval:ste:26769"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99966" version="1" comment="finch-devel is earlier than 0:2.6.6-32.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:28043"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99911" version="1" comment="pidgin is earlier than 0:2.6.6-32.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:28043"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99785" version="1" comment="libpurple-perl is earlier than 0:2.6.6-32.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:28043"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100512" version="1" comment="libpurple-devel is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100505" version="1" comment="pidgin-devel is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100487" version="1" comment="pidgin is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100448" version="1" comment="libpurple-devel is earlier than 0:2.6.6-32.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:28043"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100426" version="1" comment="finch is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100413" version="1" comment="libpurple-perl is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100391" version="1" comment="pidgin-perl is earlier than 0:2.6.6-32.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:28043"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100321" version="1" comment="pidgin-perl is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100258" version="1" comment="pidgin-devel is earlier than 0:2.6.6-32.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:28043"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100252" version="1" comment="pidgin-docs is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14724"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100193" version="1" comment="libpurple is earlier than 0:2.6.6-32.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:28043"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100189" version="1" comment="libpurple-tcl is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100181" version="1" comment="finch-devel is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100119" version="1" comment="libpurple is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100061" version="1" comment="finch is earlier than 0:2.6.6-32.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:28043"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100046" version="1" comment="libpurple-tcl is earlier than 0:2.6.6-32.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:28043"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99675" version="1" comment="glibc-headers is earlier than 0:2.5-49.el5_5.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13936"/>
      <state state_ref="oval:org.mitre.oval:ste:27669"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99437" version="1" comment="glibc is earlier than 0:2.5-49.el5_5.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14142"/>
      <state state_ref="oval:org.mitre.oval:ste:27669"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99419" version="1" comment="nscd is earlier than 0:2.5-49.el5_5.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14360"/>
      <state state_ref="oval:org.mitre.oval:ste:27669"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99370" version="1" comment="glibc-devel is earlier than 0:2.5-49.el5_5.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14346"/>
      <state state_ref="oval:org.mitre.oval:ste:27669"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98832" version="1" comment="glibc-utils is earlier than 0:2.5-49.el5_5.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14059"/>
      <state state_ref="oval:org.mitre.oval:ste:27669"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98818" version="1" comment="glibc-common is earlier than 0:2.5-49.el5_5.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14374"/>
      <state state_ref="oval:org.mitre.oval:ste:27669"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98885" version="1" comment="kernel-PAE is earlier than 0:2.6.18-274.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14641"/>
      <state state_ref="oval:org.mitre.oval:ste:27300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98845" version="1" comment="kernel-xen-devel is earlier than 0:2.6.18-274.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14821"/>
      <state state_ref="oval:org.mitre.oval:ste:27300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98843" version="1" comment="kernel-kdump is earlier than 0:2.6.18-274.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:27300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98836" version="1" comment="kernel-headers is earlier than 0:2.6.18-274.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:27300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98817" version="1" comment="kernel-doc is earlier than 0:2.6.18-274.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:27300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98746" version="1" comment="kernel-debug is earlier than 0:2.6.18-274.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:27300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98712" version="1" comment="kernel-PAE-devel is earlier than 0:2.6.18-274.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14863"/>
      <state state_ref="oval:org.mitre.oval:ste:27300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98709" version="1" comment="kernel-debug-devel is earlier than 0:2.6.18-274.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:27300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98549" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.18-274.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:27300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98526" version="1" comment="kernel is earlier than 0:2.6.18-274.12.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:27300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98407" version="1" comment="kernel-devel is earlier than 0:2.6.18-274.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:27300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98114" version="1" comment="kernel-xen is earlier than 0:2.6.18-274.12.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14710"/>
      <state state_ref="oval:org.mitre.oval:ste:27300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99159" version="1" comment="squid is earlier than 7:2.6.STABLE21-6.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14403"/>
      <state state_ref="oval:org.mitre.oval:ste:27649"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99266" version="1" comment="openssl-perl is earlier than 0:0.9.8e-12.el5_4.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:27679"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99133" version="1" comment="openssl-devel is earlier than 0:0.9.8e-12.el5_4.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:27679"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98756" version="1" comment="openssl is earlier than 0:0.9.8e-12.el5_4.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:27679"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98522" version="1" comment="firefox is earlier than 0:3.6.22-1.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27194"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98450" version="1" comment="xulrunner is earlier than 0:1.9.2.22-1.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:26927"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98413" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.22-1.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:26708"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98348" version="1" comment="firefox is earlier than 0:3.6.22-1.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26824"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98144" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.22-1.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:26927"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98050" version="1" comment="xulrunner is earlier than 0:1.9.2.22-1.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:26708"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98592" version="1" comment="firefox is earlier than 0:3.6.23-2.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26667"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98580" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.23-1.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27010"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98441" version="1" comment="xulrunner is earlier than 0:1.9.2.23-1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27133"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98437" version="1" comment="xulrunner is earlier than 0:1.9.2.23-1.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27010"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98338" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.23-1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27133"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98221" version="1" comment="firefox is earlier than 0:3.6.23-2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27460"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99953" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-3.1.13.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:27979"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99903" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-3.1.13.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:27979"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99792" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-3.1.13.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:27979"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99398" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-3.1.13.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:27775"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100373" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-3.1.13.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:27979"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100331" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-3.1.13.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:27775"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100267" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-3.1.13.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:27775"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100233" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-3.1.13.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:27979"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100218" version="1" comment="ja